dreamhands

Publisher Information

dreamhands is a software publisher located in Haewoondae-gu, Busan in Korea*. The company is a primary distributor of unwanted software. There is one additional code signing certificate issued to this publisher.
Remove dreamhands Malware - Powered by Reason Core Security
Authority:
Thawte, Inc.

Valid from:
1/19/2013 9:00:00 AM

Valid to:
2/19/2014 8:59:59 AM

Subject:
CN=dreamhands, OU=Dev. Team, O=dreamhands, L=Haewoondae-gu, S=Busan, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
0b697326e41b037e18a3a60272dce067

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.dreamhands, PUP.Installer.dreamhands, PUP.dreamhands (M), PUP.dreamhands.Installer (M)
100.00%

NANO AntiVirus
Riskware.Win32.Agent.dagpce
7.14%

Dr.Web
BackDoor.Infector.133
7.14%

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
7.14%

1 / 68      (Adware)
maxdisk.exe  (0db681496474808010d6684679465186)

1 / 68      (Adware)
maxdisk.exe  (f96d2e4234c85b57e628cdada3792264)

1 / 68      (Adware)
NediskWebControl.dll (NediskWebControl by dreamhands)  (dd715dbda9064a88e6086cf0354875ad)

1 / 68      (Adware)
NediskDown.exe (by dreamhands)  (6f31bb872ad04dc71912a2368f10b411)

1 / 68      (Adware)
NediskUp.exe (by dreamhands)  (04c7bae0a233dfabde6fac319daae6e5)

1 / 68      (Adware)
NediskWebControl.dll (NediskWebControl by dreamhands)  (8d1bb64395be06a4da28ac5355759e97)

1 / 68      (Adware)
mfileup.exe  (9363684dc55f36099694419b30311c3f)

4 / 68      (Adware)
setup.exe  (3e793cb0741ab8f8975b76e09fcbd4d3)

1 / 68      (Adware)
mfileup.exe  (cad703ccda4afc30977591b58f9ac2f9)

1 / 68      (Adware)
MaxDiskAx.ocx (by dreamhands)  (4d057c234581a9833b7bf725b0b82ddc)

1 / 68      (Adware)
mfiledown.exe  (5936dd7940049ec31f6af938148f0b4b)

1 / 68      (Adware)
mfileup.exe  (452f5e64b35783ca8cd051ace4e2a00a)

1 / 68      (Adware)
NediskDown.exe (by dreamhands)  (8c032ad72f91ecf00563e3db9e75da3a)

1 / 68      (Adware)
NediskUp.exe (by dreamhands)  (1a622b3656240e5019df62569a779e5d)

The following certificate is also signed by dreamhands.

3DAC2BFA171181BF28AC28630D02C5F0  (Jan 17, 2012 to Jan 17, 2013)

Remove dreamhands Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to dreamhands by Thawte, Inc. on January 19, 2013 with the serial number '0b697326e41b037e18a3a60272dce067'.