HelperApp.exe

SweetPacks Updater for Chrome

SweetIM Technologies Ltd

This is part of the Montera web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The application HelperApp.exe by SweetIM Technologies has been detected as adware by 6 anti-malware scanners. This will modify the wbe browser's home and search pages and search provider as well as display various advertisements. The file has been seen being downloaded from download.sweetpacks.com.
Publisher:
SweetIM Technologies Ltd.  (signed by SweetIM Technologies Ltd)

Product:
SweetPacks Updater for Chrome

Version:
1, 1, 0, 2

MD5:
c7ac135ae7d6ff2e2b91cef4e5388f28

SHA-1:
e1c99225c4c16710de3af3d52300e1e943f7c84f

SHA-256:
a59c49336b9f97f783bd0e1d46327558852875e9196aa72d31a077732719958e

Scanner detections:
6 / 68

Status:
Adware

Analysis date:
1/12/2025 4:19:41 PM UTC  (today)

Scan engine
Detection
Engine version

Boost by Reason
Adware.SweetIM.J
2013.8.28.0

Clam AntiVirus
Win.Trojan.Rbot-486
0.98/18155

Dr.Web
Adware.SweetIM.24
9.0.1.0240

Malwarebytes
PUP.Optional.SweetIM
v2013.11.26.03

Reason Heuristics
PUP.SweetIM.J
14.8.7.19

VIPRE Antivirus
Sweetpacks/SweetIM
23800

File size:
889.3 KB (910,608 bytes)

Product version:
1.1.0.2

Copyright:
Copyright © 2012 SweetIM Technologies Ltd.

Original file name:
HelperApp.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\helperapp.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/9/2011 4:00:00 PM

Valid to:
2/4/2014 3:59:59 PM

Subject:
CN=SweetIM Technologies Ltd, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=SweetIM Technologies Ltd, L=Ra'anana, S=Israel, C=IL

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5E3BF2B52DA9EA7F1B539A7F018F4EC6

File PE Metadata
Compilation timestamp:
1/9/2013 7:09:53 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:Wd+VHaZjMS4cTVHjzUie8PVlHtVzBLmlM2DRRGf0eUfMQoZZhZmxm+OGLu+s6pYf:WdlRRe8PVlHsl1D1EQoVsx5dHTUxt

Entry address:
0x3CB22

Entry point:
E8, 87, 75, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 53, 33, DB, 39, 5D, 14, 75, 20, E8, 41, 34, 00, 00, 53, 53, 53, 53, 53, C7, 00, 16, 00, 00, 00, E8, 50, FB, FF, FF, 83, C4, 14, 83, C8, FF, E9, C5, 00, 00, 00, 56, 8B, 75, 0C, 57, 8B, 7D, 10, 3B, FB, 74, 24, 3B, F3, 75, 20, E8, 11, 34, 00, 00, 53, 53, 53, 53, 53, C7, 00, 16, 00, 00, 00, E8, 20, FB, FF, FF, 83, C4, 14, 83, C8, FF, E9, 93, 00, 00, 00, C7, 45, EC, 42, 00, 00, 00, 89, 75, E8, 89, 75, E0, 81, FF, FF, FF, FF, 3F, 76, 09, C7...
 
[+]

Entropy:
6.6682

Code size:
379.5 KB (388,608 bytes)

The file HelperApp.exe has been seen being distributed by the following URL.

Remove HelperApp.exe - Powered by Reason Core Security