What is THXHelper22ad.exe?

THXHelper22ad.exe is digitally signed by Razer USA Ltd..

THXHelper22ad.exe is usually located in the 'C:\Program Files (x86)\Razer\THXVAD\Drivers\x64\' folder.

None of the anti-virus scanners at VirusTotal reports anything malicious about THXHelper22ad.exe.

If you have additional information about the file, please share it with the FreeFixer users by posting a comment at the bottom of this page.

Vendor and version information [?]

THXHelper22ad.exe does not have any version or vendor information.

Digital signatures [?]

THXHelper22ad.exe has a valid digital signature.

PropertyValue
Signer nameRazer USA Ltd.
Certificate issuer nameSymantec Class 3 SHA256 Code Signing CA
Certificate serial number3737aade9f722181eb6ea4002165fbe1

VirusTotal report

None of the 72 anti-virus programs at VirusTotal detected the THXHelper22ad.exe file.

None of the 72 anti-virus programs detected the THXHelper22ad.exe file.

Sandbox Report

The following information was gathered by executing the file inside Cuckoo Sandbox.

Summary

Successfully executed process in sandbox.

Summary

{
    "mutex": [
        "Global\\THXMutex-22AD-cuck"
    ],
    "guid": [
        "{ba43e354-d704-4465-8bc2-af58083b38c2}",
        "{a95664d2-9614-4f35-a746-de8db63617e6}",
        "{bcde0395-e52f-467c-8e3d-c4579291692e}",
        "{3b8e5435-3a70-483e-a8b5-ea7c0c0eb76b}"
    ],
    "regkey_opened": [
        "HKEY_LOCAL_MACHINE\\Software\\THX\\Settings"
    ],
    "regkey_read": [
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\MMDevices\\Audio\\Render\\{c8ce7349-e519-42ea-bfb7-698f1844ee25}\\Properties\\{026e516e-b814-414b-83cd-856d6fef4822},2",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\OLE\\MaximumAllowedAllocationSize",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\MMDevices\\Audio\\Render\\{c8ce7349-e519-42ea-bfb7-698f1844ee25}\\Properties\\{da29e02b-e54b-46f2-a15d-27a5d25616d6},0",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\MMDevices\\Audio\\Render\\{6fcf1fb3-47c2-4dea-98cf-b6fd0420a46f}\\Protocol",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\MMDevices\\Audio\\Render\\{c8ce7349-e519-42ea-bfb7-698f1844ee25}\\Protocol",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\MMDevices\\Audio\\Render\\{c8ce7349-e519-42ea-bfb7-698f1844ee25}\\Properties\\{a45c254e-df1c-4efd-8020-67d146a850e0},2",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\MMDevices\\Audio\\Render\\{6fcf1fb3-47c2-4dea-98cf-b6fd0420a46f}\\DeviceState",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\MMDevices\\Audio\\Render\\{c8ce7349-e519-42ea-bfb7-698f1844ee25}\\DeviceState",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\MMDevices\\Audio\\Render\\{c8ce7349-e519-42ea-bfb7-698f1844ee25}\\Properties\\{b3f8fa53-0004-438e-9003-51a46e139bfc},2",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\MMDevices\\Audio\\Render\\{c8ce7349-e519-42ea-bfb7-698f1844ee25}\\Properties\\{b3f8fa53-0004-438e-9003-51a46e139bfc},6"
    ],
    "dll_loaded": [
        "MMDEVAPI.DLL",
        "kernel32",
        "api-ms-win-core-fibers-l1-1-1",
        "api-ms-win-core-localization-l1-2-1",
        "api-ms-win-appmodel-runtime-l1-1-1",
        "api-ms-win-core-synch-l1-2-0",
        "dwmapi.dll",
        "ole32.dll",
        "SHLWAPI.dll",
        "ext-ms-win-kernel32-package-current-l1-1-0",
        "C:\\Windows\\system32\\uxtheme.dll"
    ]
}

Generic

[
    {
        "process_path": "C:\\Users\\cuck\\AppData\\Local\\Temp\\066cf7cb4493a8a457d89d87c522a72dedbc0fce3c60adcf87252f9b7a3a4296.bin",
        "process_name": "066cf7cb4493a8a457d89d87c522a72dedbc0fce3c60adcf87252f9b7a3a4296.bin",
        "pid": 1268,
        "summary": {
            "mutex": [
                "Global\\THXMutex-22AD-cuck"
            ],
            "guid": [
                "{ba43e354-d704-4465-8bc2-af58083b38c2}",
                "{a95664d2-9614-4f35-a746-de8db63617e6}",
                "{bcde0395-e52f-467c-8e3d-c4579291692e}",
                "{3b8e5435-3a70-483e-a8b5-ea7c0c0eb76b}"
            ],
            "regkey_opened": [
                "HKEY_LOCAL_MACHINE\\Software\\THX\\Settings"
            ],
            "regkey_read": [
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\MMDevices\\Audio\\Render\\{c8ce7349-e519-42ea-bfb7-698f1844ee25}\\Properties\\{026e516e-b814-414b-83cd-856d6fef4822},2",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\OLE\\MaximumAllowedAllocationSize",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\MMDevices\\Audio\\Render\\{c8ce7349-e519-42ea-bfb7-698f1844ee25}\\Properties\\{da29e02b-e54b-46f2-a15d-27a5d25616d6},0",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\MMDevices\\Audio\\Render\\{6fcf1fb3-47c2-4dea-98cf-b6fd0420a46f}\\Protocol",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\MMDevices\\Audio\\Render\\{c8ce7349-e519-42ea-bfb7-698f1844ee25}\\Protocol",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\MMDevices\\Audio\\Render\\{c8ce7349-e519-42ea-bfb7-698f1844ee25}\\Properties\\{a45c254e-df1c-4efd-8020-67d146a850e0},2",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\MMDevices\\Audio\\Render\\{6fcf1fb3-47c2-4dea-98cf-b6fd0420a46f}\\DeviceState",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\MMDevices\\Audio\\Render\\{c8ce7349-e519-42ea-bfb7-698f1844ee25}\\DeviceState",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\MMDevices\\Audio\\Render\\{c8ce7349-e519-42ea-bfb7-698f1844ee25}\\Properties\\{b3f8fa53-0004-438e-9003-51a46e139bfc},2",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\MMDevices\\Audio\\Render\\{c8ce7349-e519-42ea-bfb7-698f1844ee25}\\Properties\\{b3f8fa53-0004-438e-9003-51a46e139bfc},6"
            ],
            "dll_loaded": [
                "MMDEVAPI.DLL",
                "kernel32",
                "api-ms-win-core-fibers-l1-1-1",
                "api-ms-win-core-localization-l1-2-1",
                "api-ms-win-appmodel-runtime-l1-1-1",
                "api-ms-win-core-synch-l1-2-0",
                "dwmapi.dll",
                "ole32.dll",
                "SHLWAPI.dll",
                "ext-ms-win-kernel32-package-current-l1-1-0",
                "C:\\Windows\\system32\\uxtheme.dll"
            ]
        },
        "first_seen": 1586710385.59375,
        "ppid": 2724
    },
    {
        "process_path": "C:\\Windows\\System32\\lsass.exe",
        "process_name": "lsass.exe",
        "pid": 476,
        "summary": {},
        "first_seen": 1586710385.3125,
        "ppid": 376
    }
]

Signatures

[
    {
        "markcount": 1,
        "families": [],
        "description": "Checks if process is being debugged by a debugger",
        "severity": 1,
        "marks": [
            {
                "call": {
                    "category": "system",
                    "status": 0,
                    "stacktrace": [],
                    "last_error": 0,
                    "nt_status": -1073741772,
                    "api": "IsDebuggerPresent",
                    "return_value": 0,
                    "arguments": {},
                    "time": 1586710386.09375,
                    "tid": 2740,
                    "flags": {}
                },
                "pid": 1268,
                "type": "call",
                "cid": 154
            }
        ],
        "references": [],
        "name": "checks_debugger"
    },
    {
        "markcount": 1,
        "families": [],
        "description": "This executable has a PDB path",
        "severity": 1,
        "marks": [
            {
                "category": "pdb_path",
                "ioc": "C:\\build\\THXAPO-RPU0-R22ADX64\\thx-apo\\solutions\\VAD\\x64\\Release\\THXHelper22AD.pdb",
                "type": "ioc",
                "description": null
            }
        ],
        "references": [],
        "name": "has_pdb"
    },
    {
        "markcount": 1,
        "families": [],
        "description": "The executable contains unknown PE section names indicative of a packer (could be a false positive)",
        "severity": 1,
        "marks": [
            {
                "category": "section",
                "ioc": ".gfids",
                "type": "ioc",
                "description": null
            }
        ],
        "references": [],
        "name": "pe_features"
    }
]

Yara

The Yara rules did not detect anything in the file.

Network

{
    "tls": [],
    "udp": [
        {
            "src": "192.168.56.101",
            "dst": "192.168.56.255",
            "offset": 546,
            "time": 3.108842134475708,
            "dport": 137,
            "sport": 137
        },
        {
            "src": "192.168.56.101",
            "dst": "192.168.56.255",
            "offset": 5226,
            "time": 9.109963178634644,
            "dport": 138,
            "sport": 138
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 7070,
            "time": 3.044722080230713,
            "dport": 5355,
            "sport": 51001
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 7398,
            "time": 1.1046462059020996,
            "dport": 5355,
            "sport": 53595
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 7726,
            "time": 3.080907106399536,
            "dport": 5355,
            "sport": 53848
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 8054,
            "time": 1.6779839992523193,
            "dport": 5355,
            "sport": 54255
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 8382,
            "time": -0.06872892379760742,
            "dport": 5355,
            "sport": 55314
        },
        {
            "src": "192.168.56.101",
            "dst": "239.255.255.250",
            "offset": 8710,
            "time": 1.3602941036224365,
            "dport": 1900,
            "sport": 1900
        },
        {
            "src": "192.168.56.101",
            "dst": "239.255.255.250",
            "offset": 28120,
            "time": 1.316709041595459,
            "dport": 3702,
            "sport": 49152
        },
        {
            "src": "192.168.56.101",
            "dst": "239.255.255.250",
            "offset": 36504,
            "time": 3.155595064163208,
            "dport": 1900,
            "sport": 53598
        }
    ],
    "dns_servers": [],
    "http": [],
    "icmp": [],
    "smtp": [],
    "tcp": [],
    "smtp_ex": [],
    "mitm": [],
    "hosts": [],
    "pcap_sha256": "d9d6f4102f5754d7ec7e7da842f30caec7b41d5c600600a3dc9cfc9d3374544d",
    "dns": [],
    "http_ex": [],
    "domains": [],
    "dead_hosts": [],
    "sorted_pcap_sha256": "4e6ac4614291ddf88e79b19eb813f32b8e2a32f2d904bab9ecd60e759c7ebed5",
    "irc": [],
    "https_ex": []
}

Screenshots

Screenshot from the sandboxScreenshot from the sandboxScreenshot from the sandboxScreenshot from the sandboxScreenshot from the sandbox

Hashes [?]

PropertyValue
MD567227ddd2b2ad8a04096d2803114af4d
SHA256066cf7cb4493a8a457d89d87c522a72dedbc0fce3c60adcf87252f9b7a3a4296

Error Messages

These are some of the error messages that can appear related to thxhelper22ad.exe:

thxhelper22ad.exe has encountered a problem and needs to close. We are sorry for the inconvenience.

thxhelper22ad.exe - Application Error. The instruction at "0xXXXXXXXX" referenced memory at "0xXXXXXXXX". The memory could not be "read/written". Click on OK to terminate the program.

thxhelper22ad.exe has stopped working.

End Program - thxhelper22ad.exe. This program is not responding.

thxhelper22ad.exe is not a valid Win32 application.

thxhelper22ad.exe - Application Error. The application failed to initialize properly (0xXXXXXXXX). Click OK to terminate the application.

What will you do with the file?

To help other users, please let us know what you will do with the file:



What did other users do?

The poll result listed below shows what users chose to do with the file. 51% have voted for removal. Based on votes from 57 users.

User vote results: There were 29 votes to remove and 28 votes to keep

NOTE: Please do not use this poll as the only source of input to determine what you will do with the file.

Malware or legitimate?

If you feel that you need more information to determine if your should keep this file or remove it, please read this guide.

Please select the option that best describe your thoughts on the information provided on this web page


Free online surveys

And now some shameless self promotion ;)

A screenshot of FreeFixer's scan result.Hi, my name is Roger Karlsson. I've been running this website since 2006. I want to let you know about the FreeFixer program. FreeFixer is a freeware tool that analyzes your system and let you manually identify unwanted programs. Once you've identified some malware files, FreeFixer is pretty good at removing them. You can download FreeFixer here. It runs on Windows 2000/XP/2003/2008/2016/2019/Vista/7/8/8.1/10. Supports both 32- and 64-bit Windows.

If you have questions, feedback on FreeFixer or the freefixer.com website, need help analyzing FreeFixer's scan result or just want to say hello, please contact me. You can find my email address at the contact page.

Comments

Please share with the other users what you think about this file. What does this file do? Is it legitimate or something that your computer is better without? Do you know how it was installed on your system? Did you install it yourself or did it come bundled with some other software? Is it running smoothly or do you get some error message? Any information that will help to document this file is welcome. Thank you for your contributions.

I'm reading all new comments so don't hesitate to post a question about the file. If I don't have the answer perhaps another user can help you.

XxMLGGamerXx writes

1 thumb

This software is is digitally signed by Razer USA Ltd. And is not considered malware if you don`t believe us then scan it with your antivirus yourself

# 21 Dec 2020, 10:56

AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA writes

0 thumbs

I agree with u XxMLGGamerXx.

# 21 Dec 2020, 11:01

Y E S writes

0 thumbs

Y E S

# 21 Dec 2020, 11:02

Roger Karlsson writes

0 thumbs

Agreed, THXHelper22ad.exe is digitally signed by Razer. No malware there.

# 30 Dec 2020, 4:35

Hulklion writes

0 thumbs

Je pense qu'il est lier a un programme instaler avec un casque de marque RAZER donc pour moi sans danger .

# 24 Mar 2023, 23:30

how-to-kill-yourself.com writes

0 thumbs

Suicide is a complex issue that touches countless lives worldwide.
It is often connected to psychological struggles, such as anxiety, stress, or addiction problems.
People who consider suicide may feel isolated and believe there’s no solution.
<a href="https://how-to-kill-yourself.com/">how to commit suicide </a>
It is important to spread knowledge about this subject and offer a helping hand.
Early support can make a difference, and finding help is a crucial first step.
If you or someone you know is in crisis, please seek help.
You are not alone, and help is available.

# 6 Apr 2025, 1:23

JonahPoerm writes

0 thumbs

Здесь вам открывается шанс испытать обширной коллекцией игровых слотов.
Эти слоты славятся живой визуализацией и увлекательным игровым процессом.
Каждый игровой автомат предоставляет особые бонусные возможности, увеличивающие шансы на выигрыш.
<a href="https://tiendadesoftware.com.mx/1win-official-website-for-betting-and-casino-in-108/">one win</a>
Игра в слоты подходит игроков всех уровней.
Можно опробовать игру без ставки, а затем перейти к игре на реальные деньги.
Испытайте удачу и насладитесь неповторимой атмосферой игровых автоматов.

# 7 Apr 2025, 4:33

bs2best.markets writes

0 thumbs

Сайт BlackSprut — это хорошо известная точек входа в darknet-среде, предоставляющая разнообразные сервисы для пользователей.
На платформе доступна удобная навигация, а структура меню простой и интуитивный.
Участники отмечают быструю загрузку страниц и постоянные обновления.
<a href="https://bs2best.markets/blacksprut-ploshchadki.html">bs2best.markets</a>
BlackSprut ориентирован на приватность и безопасность при использовании.
Если вы интересуетесь теневые платформы, BlackSprut может стать удобной точкой старта.
Перед началом не лишним будет прочитать информацию о работе Tor.

# 10 Apr 2025, 3:59

полис осаго writes

0 thumbs

Приобретение страхового полиса для заграничной поездки — это разумное решение для защиты здоровья путешественника.
Документ покрывает медицинскую помощь в случае несчастного случая за границей.
К тому же, полис может охватывать возмещение затрат на транспортировку.
<a href="https://icforce.ru/voprosy-strahovanija/news-1-strahovanija-vyezzhajushhih-za-rubezh-i-kak-vybrat-podhodjashhij-polis-i-izbezhat-problem-sovety-jekspertov-konferencii/">страховка авто</a>
Некоторые государства требуют предоставление документа для получения визы.
Если нет страховки медицинские расходы могут быть финансово обременительными.
Приобретение документа заранее

# 26 Apr 2025, 7:47

Leave a reply