dreamhands

Publisher Information

dreamhands is a software publisher located in "Haeundae-gu ", Busan in Korea*. The company is a primary distributor of unwanted software. There is one additional code signing certificate issued to this publisher.
Remove dreamhands Malware - Powered by Reason Core Security
Authority:
Thawte, Inc.

Valid from:
1/17/2012 9:00:00 AM

Valid to:
1/17/2013 8:59:59 AM

Subject:
CN=dreamhands, O=dreamhands, L="Haeundae-gu ", S=Busan, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
3dac2bfa171181bf28ac28630d02c5f0

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.dreamhands, PUP.Installer.dreamhands, PUP.dreamhands.Installer (M), PUP.dreamhands (M)
100.00%

avast!
Win32:Adware-gen [Adw], NSIS:Malware-gen [Trj], Win32:Trojan-gen, Win32:Adware-APO [PUP]
46.15%

Fortinet FortiGate
Riskware/Kraddare, W32/Downloader_a.CNH!tr, W32/Delf.AOU!tr.dldr
46.15%

Trend Micro House Call
ADW_KRADDARE, TROJ_SPNR.1ACC13, TROJ_GEN.F47V0131, TROJ_GEN.F47V0214, TROJ_GEN.F47V0102
38.46%

McAfee Web Gateway
Artemis!88EFA742BFAC, Artemis!A1D39B889AD1, Artemis!1C29E6CEDF2B
30.77%

AhnLab V3 Security
PUP/Win32.MulDown
30.77%

McAfee
Artemis!88EFA742BFAC, Artemis!F58BFD146F77, Artemis!A1D39B889AD1
23.08%

Comodo Security
Heur.Suspicious, TrojWare.Win32.Trojan.Agent.Gen, TrojWare.Win32.StartPage.~FC
23.08%

AVG
Generic5, Win32/DH{gQwggRITJCIlATYK}, Downloader.Generic13
23.08%

MicroWorld eScan
Trojan.Generic.KD.843235, Gen:Trojan.StartPage.tq0@aWlUcKmG
15.38%

1 / 68      (Adware)
applanet_3.0.apk.exe (Download Launcher)  (861c2250da5db21a6f36ab7e3a9a44c2)

1 / 68      (Adware)
misofiledown.exe  (9f5ff87848cbcf48446f4f264883af81)

1 / 68      (Adware)
MisoFileService.exe  (b50fd2a6cc52218b05f6ec8054ad8b97)

1 / 68      (Adware)
d3dx9_43.dll.exe (Download Launcher)  (448653b82ed01be759b617dc7e32b2cd)

4 / 68      (Adware)
noiq.zip.exe (Download Launcher)  (a8d9e313fcdf979a39bcae059250c4fb)

5 / 68      (Adware)
minecraft_1.2.5.zip.exe (Download Launcher)  (0f8387449865097f7b9fb295d3079684)

4 / 68      (Adware)
setup_oc4520e.exe (Download Launcher)  (1cfab1962c87a8cc8c51dddd9547b1c6)

7 / 68      (Adware)
poketmonster_black2.nds.exe (Download Launcher)  (1c29e6cedf2b7ef3f448f37629c2e13f)

23 / 68    (Adware)
simdisksetup.exe  (a1d39b889ad13972f80c02a3ca01c11f)

3 / 68      (Adware)
simdisk.exe  (0a271f91a9602c9b7d1a47a7d6e31754)

1 / 68      (Adware)
SimDiskAx.ocx (by dreamhands)  (c9375a35f3b5ed01a19f549ef446c8a5)

9 / 68      (Adware)
uninstall_smartwinkey.exe  (f58bfd146f7701791fd0f2b38b295d4d)

23 / 68    (Adware)
smartwinkey_smartkey1.exe  (88efa742bfac081e15c5eb1970398e40)

The following certificate is also signed by dreamhands.

0B697326E41B037E18A3A60272DCE067  (Jan 19, 2013 to Feb 19, 2014)

Remove dreamhands Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to dreamhands by Thawte, Inc. on January 17, 2012 with the serial number '3dac2bfa171181bf28ac28630d02c5f0'.