wow_helper.exe

Shan Feng

The application wow_helper.exe by Shan Feng has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Shan Feng  (signed and verified)

MD5:
fc710ac4977af47eaa63a5c3faf7b3a5

SHA-1:
ff007b0540d2646b83856366b4751a9d2e31c513

SHA-256:
51802e4f02b0ceeb619abdc665c120d121cb94613ce48f2f57669a78548fbde5

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
1/13/2025 3:50:34 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Elex (M)
16.8.13.5

File size:
71.2 KB (72,920 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\Program Files\ghokswa browser\ghokswa\wow_helper.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
10/22/2015 10:00:00 PM

Valid to:
10/22/2016 9:59:59 PM

Subject:
CN=Shan Feng, OU=Individual Developer, O=No Organization Affiliation, L=Beijing, S=Beijing, C=CN

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
5BF17FB97476F1DA0D6F0CE492B01CD5

File PE Metadata
Compilation timestamp:
2/3/2009 5:16:59 PM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
384:gPR5ZgbY/+FkrZ8TkOmOXsjhJS3Hoy806la3WLQnR0igletinfePPLFQdYMD:yRqY2Ep+XsF83Ho9roWLQyiYm4YMD

Entry address:
0x2430

Code size:
42 KB (43,008 bytes)

Remove wow_helper.exe - Powered by Reason Core Security