multiplyroi_google-chrome.exe

Helios Systems LLC

The application multiplyroi_google-chrome.exe by Helios Systems has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from files4.file-mirror.info.
Publisher:
Helios Systems LLC  (signed and verified)

MD5:
6f61e99c08ce1a4c57e26ec1c058b8a3

SHA-1:
5f4413e863f1c306849f82ae0eb53edb8a4e4d4c

SHA-256:
25d72dcd6a5f12b94163b35638af1cb0f071e9f041b12935490a6f8e2d45d746

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
2/25/2025 2:28:16 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.DownloadAdmin.HeliosSy.Installer (M)
16.4.8.9

File size:
832.6 KB (852,552 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\multiplyroi_google-chrome.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/1/2014 8:00:00 PM

Valid to:
6/4/2016 7:59:59 PM

Subject:
CN=Helios Systems LLC, O=Helios Systems LLC, L=Wilmington, S=Delaware, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
70C15F05936729D95E660D0642F059AF

File PE Metadata
Compilation timestamp:
12/7/2014 11:56:37 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:E9jnxpJA9Kua6nPQSQsTnmc0Q9FxDNiZzSfOr0+z3962z7NbkGfxReei:4jxpW93nn0InTJDN2efOr0+kaVxRi

Entry address:
0x3522

Entry point:
81, EC, 78, 01, 00, 00, 53, 55, 56, 33, DB, C6, 44, 24, 0C, 20, 57, 8B, EB, BF, A0, 83, 40, 00, 8B, F3, E8, FC, 3C, 00, 00, FF, 15, 08, 87, 40, 00, 68, 01, 80, 00, 00, FF, 15, AC, 80, 40, 00, 53, FF, 15, 0C, 87, 40, 00, 6A, 08, A3, C4, 4C, 42, 00, E8, 26, 2A, 00, 00, 53, 68, 60, 01, 00, 00, A3, 50, 44, 42, 00, 8D, 44, 24, 30, 50, 53, 68, E3, 83, 40, 00, FF, 15, 50, 81, 40, 00, 68, E4, 83, 40, 00, 68, 60, 44, 42, 00, E8, 40, 2C, 00, 00, FF, 15, A8, 80, 40, 00, 50, 68, 00, A0, 42, 00, E8, 2F, 2C, 00, 00, 53...
 
[+]

Entropy:
7.4938

Packer / compiler:
Nullsoft install system v2.x

Code size:
25 KB (25,600 bytes)

The file multiplyroi_google-chrome.exe has been seen being distributed by the following URL.

Remove multiplyroi_google-chrome.exe - Powered by Reason Core Security