pgcchelper.exe

The application pgcchelper.exe has been detected as a potentially unwanted program by 4 anti-malware scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘pgcchelper’. While running, it connects to the Internet address ip170.ip-137-74-189.eu on port 80 using the HTTP protocol.
MD5:
7e396d4a774a1a4134ba6aba3b26cc6f

SHA-1:
6fc64c28956f5d941ffe08d3d7cacf6b616b4d3d

SHA-256:
783075436c1765dd0394e6a392435241e2f85d00fe2807c44df44d136106086e

Scanner detections:
4 / 68

Status:
Potentially unwanted

Analysis date:
11/23/2024 10:23:14 PM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
HW32.Pedka
1.3.0.4613

ESET NOD32
Win32/AdWare.CycloneAd.B application
6.3.12010.0

Trend Micro House Call
TROJ_GEN.F47V0926
7.2.13

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.24.3

File size:
455 KB (465,920 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\pgcchelper\pgcchelper.exe

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:lzbmScFVEvqwRD087u5+zYjPMfr14DQFu/U3buRKlemZ9DnGAeeEdzHi:J5cwv/y8C+BjdE

Entry address:
0x63228

Entry point:
55, 8B, EC, 83, C4, F4, 53, 56, 57, B8, 08, 2F, 46, 00, E8, 85, 37, FA, FF, 33, C0, 55, 68, A9, 32, 46, 00, 64, FF, 30, 64, 89, 20, B2, 01, A1, DC, 15, 46, 00, E8, 03, E4, FF, FF, A3, 60, 6B, 46, 00, 33, C0, 55, 68, 98, 32, 46, 00, 64, FF, 30, 64, 89, 20, A1, 60, 6B, 46, 00, E8, 32, F8, FF, FF, 84, C0, 74, 0A, A1, 60, 6B, 46, 00, E8, 38, F9, FF, FF, 33, C0, 5A, 59, 59, 64, 89, 10, 68, 9F, 32, 46, 00, A1, 60, 6B, 46, 00, E8, 25, FC, F9, FF, C3, E9, 3F, 03, FA, FF, EB, EE, 33, C0, 5A, 59, 59, 64, 89, 10, EB...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
393 KB (402,432 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
pgcchelper

Command:
C:\users\{user}\appdata\local\pgcchelper\pgcchelper.exe


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to parkingsrv0.dondominio.com  (37.152.88.54:80)

TCP (HTTP):
Connects to ip170.ip-137-74-189.eu  (137.74.189.170:80)

Remove pgcchelper.exe - Powered by Reason Core Security