gomhelper.exe

GRETECH

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘GomHelper’.
Publisher:
GRETECH  (signed and verified)

Version:
2017.3.15.1

MD5:
eb0480bc32e2af873f7d2f955466db95

SHA-1:
d60ab366cd06db23ed097ac5d912eff014fd7887

SHA-256:
ba6e7454d55816a07881ecc904480c4b337ba958720282ee05d3d9f0d37d13c3

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/26/2024 11:11:18 PM UTC  (a few moments ago)

File size:
1.3 MB (1,405,880 bytes)

Product version:
2017.3.15.1

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\gretech\gomhelper\gomhelper.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
12/21/2015 9:00:00 AM

Valid to:
6/17/2017 8:59:59 AM

Subject:
CN=GRETECH, O=GRETECH, L=Gangnam-gu, S=Seoul, C=KR

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
59B4F88AACBE29B5C1AE3340C2C0F244

File PE Metadata
Compilation timestamp:
3/15/2017 2:49:20 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x1231A0

Entry point:
55, 8B, EC, 83, C4, F0, B8, 18, BA, 51, 00, E8, F8, 7F, EE, FF, E8, C7, 87, FF, FF, A1, 58, 8A, 52, 00, 8B, 00, E8, 5F, 75, FE, FF, A1, 58, 8A, 52, 00, 8B, 00, B2, 01, E8, 51, 92, FE, FF, 8B, 0D, E8, 8B, 52, 00, A1, 58, 8A, 52, 00, 8B, 00, 8B, 15, C0, 24, 51, 00, E8, 51, 75, FE, FF, A1, 58, 8A, 52, 00, 8B, 00, C6, 40, 5F, 00, A1, 58, 8A, 52, 00, 8B, 00, E8, 92, 76, FE, FF, E8, 71, 40, EE, FF, 90, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.5908

Developed / compiled with:
Microsoft Visual C++

Code size:
1.1 MB (1,188,352 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
GomHelper

Command:
"C:\Program Files\gretech\gomhelper\gomhelper.exe"


Scan gomhelper.exe - Powered by Reason Core Security