helpmng.exe

GPS Module

GPS Safety

This is a setup program which is used to install the application. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘PluginContains’. The file has been seen being downloaded from rh-softwarevizual.com.
Publisher:
GPS Safety

Product:
GPS Module

Description:
Module GPS ®

Version:
2.3.8.27

MD5:
b6a2055998cc8f36bf79875b6e0d68fc

SHA-1:
36c6a2016c0e932c09dd597809da1fe06df45b0a

SHA-256:
b1b5b04d2cfcde6c87c1e98c80b45c3423cc92f3bed54411acc7f022c0b86861

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 1:44:34 PM UTC  (today)

File size:
5.5 MB (5,807,616 bytes)

Product version:
2.3.8.0

Copyright:
GPS Safety ®

Original file name:
GPService

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\helpmng.exe

File PE Metadata
Compilation timestamp:
4/11/2016 7:25:37 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:IrY3a+P0e2VcMUsNEk9LQtW6M2MXgo1TFZ/55KEBn1nkqAZifWKTb4wntb5Vqdb:IrKDcVl7zkQ6KXgoJFtKWt8TKIctb5VS

Entry address:
0x8C3547

Entry point:
E8, EC, 1F, 00, 00, E5, 36, F7, FD, 48, 77, 46, 11, 8B, 98, F1, 87, B8, 58, B9, B7, E5, FE, F2, 09, 44, 4C, 80, 5B, C2, 26, 63, 1D, 2E, 12, 0E, E5, 5C, 5C, 95, 88, 26, 24, C1, F6, 24, 4D, D0, 00, 2C, BF, BA, F6, 60, 88, D7, AC, 5C, 83, B7, 2E, AF, B9, 41, BE, 5F, 71, F4, E4, 6F, D7, 0C, 7C, B9, BE, 62, 4D, 3F, 89, F4, 5C, 7C, 19, BD, 12, 8C, 10, EE, A7, 31, A8, D1, 57, FB, 4E, D3, EE, 39, 96, 37, E1, 51, 02, 3C, 21, 56, 80, B4, 1A, 18, B8, 9B, 60, 00, 6A, A1, 6F, CB, F8, 60, E4, 61, 23, 5E, D2, 60, F3, 5B...
 
[+]

Code size:
3.1 MB (3,210,240 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
PluginContains

Command:
C:\users\{user}\appdata\local\helpmng.exe


The file helpmng.exe has been seen being distributed by the following URL.

Scan helpmng.exe - Powered by Reason Core Security