magicplus_helper.exe may be a dangerous application, according to heuristic analysis. This program triggers many of the "possible danger" criteria described in this document. It is yet unknown if magicplus_helper.exe is malware or an ok program that doesn't harm your PC. We advise you to be careful with this application.
Usually, the default name and directory where the program is stored is
C:\Program Files (x86)\MagicPlus\MagicPlus_helper.exe.
The MD5 fingerprint for this file is 110685e9e1ebe44c3fd88806436d78f2.
This program does NOT run as a Windows service. This is usually a good sign.
This application runs in 32-bit mode. It does not use the full set of features of nowadays' PC processors. This is quite normal because the makers did not upgrade it to 64-bit code.
The description extracted from the exe is magicPlus_helper.
File version stored as a property 126.96.36.199.
Legal copyright (C) Lenovo????????.
magicplus_helper.exe appears to have visible windows. This is good because it doesn't work in some kind of stealth mode. Its operation is clearly displayed to the user.
Some dangerous functions of Windows have been used, such as functions for tapping the keyboard. We recommend you to perform more in-depth research about this program.
magicplus_helper.exe has a digital signature. Today the large majority of serious programs are digitally signed.
The digital signature is broken, which indicates this app may be a virus and that somebody probably tampered with it after the signature was applied. We advise extreme caution!
Digital certificate name: LENOVO
Certificate's issuer name: VeriSign Class 3 Code Signing 2010 CA
This executable is registered to start when your computer boots. Yes
It has an uninstall string in registry, which is good. si are uninstall.