helper.exe

System Cleaner

Pointstone Software, LLC

The application helper.exe by Pointstone Software has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This file is typically installed with the program System Cleaner 7 by Pointstone Software, LLC. While running, it connects to the Internet address t1.softonicads.com on port 80 using the HTTP protocol.
Publisher:
Pointstone Software, LLC  (signed and verified)

Product:
System Cleaner

Description:
Integrator

Version:
7.5.8.330

MD5:
244554a6424706309e50c490b28e93b6

SHA-1:
88741d212e8ff2aea10f8f58a1936a3e4a33bc2c

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/27/2024 4:27:05 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Optional.Pointstone
17.2.1.14

File size:
131.6 KB (134,728 bytes)

Copyright:
Copyright © 1997 - 2016 Pointstone Software, LLC. All rights reserved.

Trademarks:
System Cleaner is a registered trademark of Pointstone Software, LLC. (United States Patent and Trademark Office registration number 2926385)

Original file name:
Integrator.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\pointstone\system cleaner 7\helper.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
11/12/2014 2:00:00 AM

Valid to:
11/13/2019 1:59:59 AM

Subject:
CN="Pointstone Software, LLC", O="Pointstone Software, LLC", L=Newark, S=DE, PostalCode=19713, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
1E600E539078A378196FBC5627EB6553

File PE Metadata
Compilation timestamp:
2/1/2017 1:38:44 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x7430

Entry point:
55, 8B, EC, B9, 2F, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 53, 56, 57, B8, E4, 62, 40, 00, E8, 2C, 9D, FF, FF, 33, C0, 55, 68, 45, 89, 40, 00, 64, FF, 30, 64, 89, 20, 33, C0, 55, 68, E7, 86, 40, 00, 64, FF, 30, 64, 89, 20, 8D, 45, E0, E8, 64, AA, FF, FF, 8B, 45, E0, BA, 64, 89, 40, 00, 8B, 08, FF, 51, 0C, A1, BC, D4, 40, 00, 8B, 00, E8, 6B, A9, FF, FF, E8, 2E, AA, FF, FF, 8B, 10, FF, 52, 04, 8D, 55, DC, 8B, 08, FF, 51, 1C, 8B, 55, DC, A1, BC, D4, 40, 00, 8B, 00, E8, 3A, A9, FF, FF, 8D, 45, D8, E8, 22, AA...
 
[+]

Entropy:
6.2421

Developed / compiled with:
Microsoft Visual C++

Code size:
33.5 KB (34,304 bytes)

The file helper.exe has been discovered within the following program.

System Cleaner 7  by Pointstone Software, LLC
Publisher's description - “Fix your PC's problems, and help prevent them from recurring with System Cleaner's suite of maintenance tools. System Cleaner restores your PC's performance, frees up wasted disk space, prevents registry corruption and protects your online privacy. Your PC is slowing down.”
www.systemcleaner.com
45% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to t1.softonicads.com  (46.28.209.23:80)

TCP (HTTP):
Connects to pointstone.com  (108.61.26.20:80)

TCP (HTTP):
Connects to a72-247-182-18.deploy.akamaitechnologies.com  (72.247.182.18:80)

TCP (HTTP):
Connects to a23-216-242-187.deploy.static.akamaitechnologies.com  (23.216.242.187:80)

Remove helper.exe - Powered by Reason Core Security