We Recommend: You Boost your PC today

Should I block it?

No, this file is 100% safe to run.

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegOpenKeyExW, RegCreateKeyExW, ImpersonateLoggedOnUser, RevertToSelf, LookupAccountSidW, CryptReleaseContext, CryptDestroyKey, CryptExportKey, CryptAcquireContextW, CryptImportKey, CryptEncrypt, CryptGenKey, CryptDecrypt, AdjustTokenPrivileges, LookupPrivilegeValueW, OpenProcessToken, StartServiceCtrlDispatcherW, RegisterServiceCtrlHandlerW, GetSecurityDescriptorLength, ControlService, DeleteService, CreateServiceW, OpenSCManagerW, OpenServiceW, CloseServiceHandle, RegisterEventSourceW, ReportEventW, DeregisterEventSource, SetServiceStatus, RegQueryValueExW, RegEnumKeyExW, RegQueryInfoKeyW, RegSetValueExW, RegCloseKey, RegDeleteValueW, RegOpenCurrentUser, GetTokenInformation, RegDeleteKeyW
iphlpapi.dll
GetBestInterface, GetAdaptersInfo
kernel32.dll
HeapAlloc, InitializeCriticalSection, GetProcessHeap, HeapFree, GetCommandLineW, LocalFree, CreateEventW, CreateThread, Sleep, GetCurrentThreadId, SetEvent, WaitForSingleObject, CreateEventA, LoadLibraryExW, FindResourceW, LoadResource, SizeofResource, MultiByteToWideChar, FreeLibrary, GetModuleFileNameW, CloseHandle, lstrcmpiW, InterlockedDecrement, InterlockedIncrement, GetModuleHandleW, GetProcAddress, DeleteCriticalSection, InitializeCriticalSectionAndSpinCount, GetLastError, LeaveCriticalSection, EnterCriticalSection, RaiseException, LoadLibraryA, LCMapStringA, GetStringTypeExW, GetStringTypeExA, FormatMessageA, lstrlenW, GetTimeFormatA, CreateDirectoryW, GetFileAttributesW, GetFileAttributesA, SetEnvironmentVariableA, CompareStringW, SetEndOfFile, CreateFileW, CreateFileA, WriteConsoleW, SetStdHandle, IsValidLocale, lstrlenA, WideCharToMultiByte, ProcessIdToSessionId, GetCurrentProcessId, FormatMessageW, GetCurrentProcess, GetVersionExW, OpenProcess, Process32NextW, Process32FirstW, CreateToolhelp32Snapshot, GetDateFormatA, GetSystemInfo, LoadLibraryW, HeapDestroy, HeapReAlloc, HeapSize, GetStringTypeW, InterlockedCompareExchange, InterlockedExchange, EncodePointer, DecodePointer, GetSystemTimeAsFileTime, TlsAlloc, TlsFree, TlsGetValue, OpenEventA, ResetEvent, TlsSetValue, ResumeThread, GetTickCount, SystemTimeToFileTime, WaitForMultipleObjects, SetWaitableTimer, CreateWaitableTimerA, RtlUnwind, HeapSetInformation, GetStartupInfoW, LCMapStringW, GetCPInfo, ExitThread, IsProcessorFeaturePresent, ExitProcess, WriteFile, GetStdHandle, HeapCreate, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, TerminateProcess, GetLocaleInfoW, SetLastError, FreeEnvironmentStringsW, GetEnvironmentStringsW, SetHandleCount, GetFileType, QueryPerformanceCounter, GetTimeZoneInformation, GetACP, GetOEMCP, IsValidCodePage, ReadFile, SetFilePointer, GetConsoleCP, GetConsoleMode, FlushFileBuffers, GetUserDefaultLCID, GetLocaleInfoA, EnumSystemLocalesA
libcurl.dll
curl_easy_cleanup, curl_easy_init, curl_easy_getinfo, curl_easy_escape, curl_easy_perform, curl_easy_setopt, curl_free
netapi32.dll
NetApiBufferFree, NetWkstaTransportEnum, NetUserGetInfo
ole32.dll
CoResumeClassObjects, CoInitializeSecurity, CoReleaseServerProcess, CoSetProxyBlanket, CoAddRefServerProcess, CoCreateInstance, StringFromGUID2, CoUninitialize, CoInitializeEx, CoRegisterClassObject, CoTaskMemAlloc, CoTaskMemRealloc, CoTaskMemFree, CoRevokeClassObject
shell32.dll
SHGetSpecialFolderPathW
user32.dll
CharUpperW, TranslateMessage, CharNextW, GetMessageW, PostThreadMessageW, DispatchMessageW, LoadStringW, LoadStringA, MessageBoxW, GetSystemMetrics
userenv.dll
UnloadUserProfile, LoadUserProfileW
wininet.dll
InternetReadFile, InternetCloseHandle, HttpOpenRequestW, HttpQueryInfoW, InternetSetOptionW, HttpSendRequestW, InternetConnectW, InternetOpenW
wtsapi32.dll
WTSEnumerateSessionsW, WTSWaitSystemEvent, WTSFreeMemory, WTSQuerySessionInformationW

HelperService.exe

Helper Service by Chinery & Heindoerfer GbR (Signed)

Version:   1.0.52.8917
MD5:   a1688a4fb2ec49d040c027ef6dc7a87b
SHA1:   cdca084056213191a9ff57961243adb0310e3381
SHA256:   e5f5768d189b590f4d8d20c13fc0f7ff5ac7c4729848f38a93d653ab0b740696

Overview

helperservice.exe runs as a service under the name PDF Architect Helper Service with extensive SYSTEM privileges (full administrator access). This is typically installed with the program PDF Architect published by pdfforge. The file is digitally signed by Chinery & Heindoerfer GbR which was issued by the Thawte certificate authority (CA).

DetailsDetails

File name:helperservice.exe
Publisher:pdfforge GbR
Product name:Helper Service
Description:PDF Architect Helper Service
Typical file path:C:\Program Files\pdf architect\helperservice.exe
File version:1.0.52.8917
Size:1.26 MB (1,324,104 bytes)
Certificate
Issued to:Chinery & Heindoerfer GbR
Authority (CA):Thawte
Effective date:Tuesday, May 29, 2012
Expiration date:Thursday, May 30, 2013
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following program will install this file
pdfforge
12% remove
PDFArchitect is a tool to easily modify your PDF files - i.e. you can merge two files, delete pages or rotate them.

BehaviorsBehaviors

Service
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'PDF Architect Helper Service'

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00005391%
0.028634%
Kernel CPU:0.00003859%
0.013761%
User CPU:0.00001532%
0.014873%
Kernel CPU time:16 ms/min
100,923,805ms/min
CPU cycles:4,024/sec
17,470,203/sec
Memory
Private memory:3.04 MB
21.59 MB
Private (maximum):8.66 MB
Private (minimum):7.66 MB
Non-paged memory:3.04 MB
21.59 MB
Virtual memory:54.66 MB
140.96 MB
Virtual memory (peak):58.16 MB
169.69 MB
Working set:7.66 MB
18.61 MB
Working set (peak):8.67 MB
37.95 MB
Page faults:2,410/min
2,039/min
I/O
I/O read transfer:3 Bytes/sec
1.02 MB/min
I/O read operations:1/sec
343/min
I/O write transfer:3 Bytes/sec
274.99 KB/min
I/O write operations:1/sec
227/min
I/O other transfer:6 Bytes/sec
448.09 KB/min
I/O other operations:1/sec
1,671/min
Resource allocations
Threads:4
12
Handles:98
600

BehaviorsProcess properties

Integrety level:System
Platform:64-bit
Command line:"C:\Program Files\pdf architect\helperservice.exe"
Owner:SYSTEM
Windows Service
Service name:PDF Architect Helper Service
Type:Win32OwnProcess
Parent process:services.exe (Services and Controller app by Microsoft)

ResourcesThreads

Averages
 
wow64.dll (Win32 Emulation on NT64 by Microsoft)
Total CPU:0.00019246%
0.272967%
Kernel CPU:0.00019246%
0.107585%
User CPU:0.00000000%
0.165382%
CPU cycles:3,603/sec
5,741,424/sec
Memory:252 KB
1.16 MB
ADVAPI32.dll
Total CPU:0.00006361%
Kernel CPU:0.00006361%
User CPU:0.00000000%
CPU cycles:1,863/sec
Memory:792 KB
HelperService.exe (main module)
Total CPU:0.00006360%
Kernel CPU:0.00000000%
User CPU:0.00006360%
CPU cycles:2,379/sec
Memory:1.28 MB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Professional 66.67%
Windows Vista Home Premium 33.33%

Distribution by countryDistribution by country

United Kingdom installs about 66.67% of Helper Service.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Samsung 66.67%
Hewlett-Packard 33.33%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE