Eltwocompany

Publisher Information

Eltwocompany is a software publisher located in Seocho-gu, Seoul in Korea*. There is one additional code signing certificate issued to this publisher.
Remove Eltwocompany Malware - Powered by Reason Core Security
Authority:
Thawte, Inc.

Valid from:
9/20/2012 9:00:00 AM

Valid to:
9/21/2013 8:59:59 AM

Subject:
CN=Eltwocompany, O=Eltwocompany, L=Seocho-gu, S=SEOUL, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
09d251f244da1f5db45ebd3c90b2568f

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.Eltwocompany.P, PUP.Eltwocompany, PUP.Eltwocompany (M), PUP.Eltwocompany.Installer (M)
100.00%

ESET NOD32
Win32/Adware.CloverPlus.AB (variant), Win32/VB.PBN (variant)
60.00%

IKARUS anti.virus
Backdoor.Win32.Runagry, Trojan.VB2, AdWare.Win32.Kwsearchguide
60.00%

VIPRE Antivirus
Trojan.Win32.Generic.pak!cobra
50.00%

Trend Micro House Call
TROJ_GEN.F47V0708, TROJ_GEN.F47V0212, Suspicious_GEN.F47V0321
40.00%

Malwarebytes
Adware.KorAd
30.00%

Comodo Security
TrojWare.Win32.TrojanDownloader.VB.PMEA, UnclassifiedMalware
30.00%

AVG
Generic9_c, Generic5
20.00%

Dr.Web
DLOADER.Trojan
20.00%

AhnLab V3 Security
PUP/Win32.HipPop
10.00%

1 / 68      (Adware)
RollingPop_U.exe (RollingPop_U by LTOB)  (6835767735143878f0cd4890b117455d)

1 / 68      (Adware)
windiscover7.exe  (d956b7e9cc2d4df806066ada4d993110)

5 / 68      (Adware)
setup_00002.exe  (1fcad3dc4562683288f018da9911a03e)

3 / 68      (Adware)
RollingPop_S.exe (RollingPop_S by LTOB)  (078b0e03b8d863315f63a813f44a7175)

5 / 68      (Adware)
windiscover1.exe  (df6bec3ee06d65a2cf1db8fddf89738c)

6 / 68      (Adware)
windiscover.EXE  (0cb421a0e5634e6d4ee752d1477092b8)

10 / 68    (Adware)
tmp00001103  (6846aed744da36bb25fb20069529be8a)

9 / 68      (Adware)
RollingPop_U.exe (RollingPop_U by LTOB)  (83fe37750c0faff74feaaa0f850019aa)

3 / 68      (Adware)
RollingPop_S.exe (RollingPop_S by LTOB)  (eedfe1a35eded5bac95c404b18d63a38)

4 / 68      (Adware)
wdc_uninstaller.exe  (e46f4a16e7bfbf136182c5faad496586)

The following certificate is also signed by Eltwocompany.

2EDC6D113F1BCA68A7DF78E66DC81620  (Sep 17, 2013 to Oct 18, 2014)

Remove Eltwocompany Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to Eltwocompany by Thawte, Inc. on September 20, 2012 with the serial number '09d251f244da1f5db45ebd3c90b2568f'.