uncheckithelper.exe

Uncheckit Module

EVANGEL TECHNOLOGY(HK) LIMITED

The application uncheckithelper.exe by EVANGEL TECHNOLOGY(HK) LIMITED has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This file is typically installed with the program Uncheckit by EVANGEL TECHNOLOGY (HK) LIMITED. While running, it connects to the Internet address server-54-192-203-37.fra50.r.cloudfront.net on port 80 using the HTTP protocol.
Publisher:
EVANGEL TECHNOLOGY (HK) LIMITED  (signed by EVANGEL TECHNOLOGY(HK) LIMITED)

Product:
Uncheckit Module

Description:
Uncheckit Helper

Version:
2.0.8.25888

MD5:
dda42a3a921f543f90b40c850ab53957

SHA-1:
372be1908a86f63f55a07eb8e7e4cec20b8ea803

SHA-256:
59ebfe6a985a045ca603bf4fc2a1e7c442c02a7a1c9972769de6034ae3d6b474

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/5/2024 10:15:45 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Evangel.Uncheckit.Meta (M)
16.6.19.12

File size:
450.8 KB (461,640 bytes)

Product version:
2.0.8.25888

Copyright:
Copyright (c) 2011-2016 EVANGEL TECHNOLOGY (HK) LIMITED

Original file name:
uncheckithelper.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\uncheckit\uncheckithelper.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
6/1/2016 7:34:14 PM

Valid to:
11/26/2016 1:27:12 AM

Subject:
CN=EVANGEL TECHNOLOGY(HK) LIMITED, O=EVANGEL TECHNOLOGY(HK) LIMITED, L=香港, S=香港, C=HK

Issuer:
CN=GlobalSign CodeSigning CA - G3, O=GlobalSign nv-sa, C=BE

Serial number:
7FB6522A8532A7ECE39AB9AE

File PE Metadata
Compilation timestamp:
6/2/2016 12:43:11 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:Fzqg05SMDT/Q6RYj807ezkYGspNX1cUrFeM/zGsGRNmxHn1dDzE2S2XB4eSN/y9p:F+gEDXRYjfezkYJpNX1fJGRIH1db9

Entry address:
0x3B4AC

Entry point:
E8, C0, 05, 00, 00, E9, 4C, FE, FF, FF, FF, 25, 18, 23, 44, 00, FF, 25, 14, 23, 44, 00, 55, 8B, EC, FF, 15, B4, 20, 44, 00, 6A, 01, A3, 34, 57, 46, 00, E8, A7, 06, 00, 00, FF, 75, 08, E8, A5, 06, 00, 00, 83, 3D, 34, 57, 46, 00, 00, 59, 59, 75, 08, 6A, 01, E8, 8D, 06, 00, 00, 59, 68, 09, 04, 00, C0, E8, 8E, 06, 00, 00, 59, 5D, C3, 55, 8B, EC, 81, EC, 24, 03, 00, 00, 6A, 17, E8, 21, 17, 00, 00, 85, C0, 74, 05, 6A, 02, 59, CD, 29, A3, 18, 55, 46, 00, 89, 0D, 14, 55, 46, 00, 89, 15, 10, 55, 46, 00, 89, 1D, 0C...
 
[+]

Code size:
259 KB (265,216 bytes)

The file uncheckithelper.exe has been discovered within the following program.

Uncheckit  by EVANGEL TECHNOLOGY (HK) LIMITED
About 5% of users remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to server-54-230-216-199.mrs50.r.cloudfront.net  (54.230.216.199:80)

TCP (HTTP):
Connects to server-54-240-186-156.mad50.r.cloudfront.net  (54.240.186.156:80)

TCP (HTTP):
Connects to server-54-240-186-84.mad50.r.cloudfront.net  (54.240.186.84:80)

TCP (HTTP):
Connects to server-54-240-186-170.mad50.r.cloudfront.net  (54.240.186.170:80)

TCP (HTTP):
Connects to server-54-230-187-75.cdg51.r.cloudfront.net  (54.230.187.75:80)

TCP (HTTP):
Connects to server-54-192-3-141.lhr5.r.cloudfront.net  (54.192.3.141:80)

TCP (HTTP):
Connects to server-54-192-3-104.lhr5.r.cloudfront.net  (54.192.3.104:80)

TCP (HTTP):
Connects to server-54-230-187-23.cdg51.r.cloudfront.net  (54.230.187.23:80)

TCP (HTTP):
Connects to server-52-84-230-121.sfo9.r.cloudfront.net  (52.84.230.121:80)

TCP (HTTP):
Connects to server-54-230-216-133.mrs50.r.cloudfront.net  (54.230.216.133:80)

TCP (HTTP):
Connects to server-54-230-163-144.jax1.r.cloudfront.net  (54.230.163.144:80)

TCP (HTTP):
Connects to server-54-192-130-83.ams50.r.cloudfront.net  (54.192.130.83:80)

TCP (HTTP):
Connects to server-52-85-77-211.lax3.r.cloudfront.net  (52.85.77.211:80)

TCP (HTTP):
Connects to server-52-85-74-249.lhr3.r.cloudfront.net  (52.85.74.249:80)

TCP (HTTP):
Connects to server-52-85-63-237.lhr50.r.cloudfront.net  (52.85.63.237:80)

TCP (HTTP):
Connects to server-54-240-186-244.mad50.r.cloudfront.net  (54.240.186.244:80)

TCP (HTTP):
Connects to server-54-230-187-47.cdg51.r.cloudfront.net  (54.230.187.47:80)

TCP (HTTP):
Connects to server-54-230-187-244.cdg51.r.cloudfront.net  (54.230.187.244:80)

TCP (HTTP):
Connects to server-54-230-141-26.sfo5.r.cloudfront.net  (54.230.141.26:80)

TCP (HTTP):
Connects to server-54-192-3-240.lhr5.r.cloudfront.net  (54.192.3.240:80)

Remove uncheckithelper.exe - Powered by Reason Core Security