shoppinhelper2_setup2c2.03.9.exe

SHelp2

The application shoppinhelper2_setup2c2.03.9.exe has been detected as a potentially unwanted program by 4 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs. The file has been seen being downloaded from d4j83swn8t881.cloudfront.net and multiple other hosts.
Publisher:
SHelp2

Product:
SHelp2

Version:
2.0

MD5:
8e624bcffcfe47f70f93fc461a85f439

SHA-1:
7ccef7b1c5795ffbf81f3d88dd5f53d25a28fe8e

SHA-256:
8c3e5694619fbe61b47e9fb6b3c93ad0711a5eb526cbb2c09e50042bdf8b460f

Scanner detections:
4 / 68

Status:
Potentially unwanted

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
11/23/2024 4:13:16 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.OutBrowse
7.1.1

avast!
Win32:Rootkit-gen [Rtk]
2014.9-140906

Baidu Antivirus
PUA.Win32.OutBrowse
4.0.3.1496

ESET NOD32
Win32/OutBrowse.AO
8.10370

File size:
10.1 MB (10,552,176 bytes)

Copyright:
© SHelp2

Trademarks:
SHelp2

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\shoppinhelper2_setup2c2.03.9.exe

File PE Metadata
Compilation timestamp:
12/5/2009 2:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
196608:QapE1abfaVIB6iBChhh/qKJewDOkjZs9Zx9arWwTVxfASfmDgwXJpYK3oi:QaOYboIwSK0W1IZbzDgwzvp

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9997

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file shoppinhelper2_setup2c2.03.9.exe has been seen being distributed by the following 2 URLs.

Remove shoppinhelper2_setup2c2.03.9.exe - Powered by Reason Core Security