goodcomms Inc.

Publisher Information

goodcomms Inc. is a software publisher located in Seongnam-si, Gyeonggi-Do in Korea*. A majority of the programs developed by the company can be classified as adware or other potentially unwanted programs. Thre are 3 additional code signing certificates issued to this publisher.
Remove goodcomms Inc. Malware - Powered by Reason Core Security
Authority:
Thawte, Inc.

Valid from:
11/11/2012 9:00:00 AM

Valid to:
12/12/2013 8:59:59 AM

Subject:
CN=goodcomms Inc., OU=marketing, O=goodcomms Inc., L=Seongnam-si, S=Gyeonggi-do, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
630e494ee04789e6cd2b37bb23aa30b7

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.GoodComms (M), PUP.GoodComms.IndigoRoseCorporation (M), PUP.GoodComms.Installer (M)
97.56%

AhnLab V3 Security
PUP/Win32.GoodComms, PUP/Win32.WebGuide, PUP/Win32.AppIs, PUP/Win32.WebCompass, Win-PUP/Helper.AppIs.98760
34.15%

nProtect
Adware/W32.KrAdword.1209296, Adware/W32.KrAdword.1240528, Adware/W32.KrAdword.48592, Adware/W32.Agent.1919432, Adware/W32.KrAdword.1016776, Adware/W32.Agent.48584, Adware/W32.KrAdword.93128
19.51%

Trend Micro House Call
TROJ_GEN.F47V0629, TROJ_GEN.F47V1223, TROJ_GEN.F47V0113, TROJ_GEN.F47V0913, ADW_KRADDARE, TROJ_GEN.F47V0318
14.63%

Malwarebytes
Adware.Kraddare, Adware.KorAd
14.63%

Antiy Labs AVL
Spyware[AdWare:not-a-virus]/Win32.MicrowinSearch, Hoax/Win32.SMUpdate
14.63%

McAfee Web Gateway
Heuristic.BehavesLike.Win32.Suspicious-BAY.K
9.76%

Dr.Web
Trojan.Popclick.47, Trojan.Adkor.55, Trojan.Adkor.98
7.32%

XVirus List
Win32.Detected
2.44%

Bkav FE
W32.Clod4e3.Trojan
2.44%

1 / 68      (PUP)
wslopencapture4.exe  (d5f752eb53b54bae95d168f1c05695dd)

1 / 68      (PUP)
isopencapture4.exe (by goodcomms)  (f580190c969e73530ee63527b2149c08)

1 / 68      (PUP)
wslgoorma.exe  (e81c71670d0c4abcacd28859ff7b7466)

1 / 68      (PUP)
isgoorma.exe (by Goodcomms)  (22d538d45854e16a4137a0603426f916)

1 / 68      (PUP)
wslfileocean.exe  (6a66831716a0e6a4c0c61eb7b7a5b3a5)

1 / 68      (PUP)
ipop.exe  (be901c55acd62b34166e1bc9f4ab9f41)

1 / 68      (PUP)
observer.dll  (a4d16a85608e2d2330fd2916aa754536)

1 / 68      (PUP)
free.exe  (2748d3d06c9654efb541e9034168f4e4)

1 / 68      (PUP)
wslfiletab.exe  (b75cc8f51a9b0d755ff6e915ae47594c)

1 / 68      (PUP)
observer.dll  (792924fec8f0093150a1a736cf7277d7)

2 / 68      (PUP)
isgoorma.exe (by Goodcomms)  (8d1e57afec6b3d6763e8ffe36ed8c546)

1 / 68      (PUP)
sideobserver.dll  (90b1aec84357ca0329b3bdcf4cdad1bc)

1 / 68      (PUP)
free.exe  (bb8209ea9b24b297c706228a632c19c5)

2 / 68      (PUP)
update.exe (TrueUpdate Client by Indigo Rose)  (ed2a6315d6597151b21eeaf38c342484)

3 / 68      (PUP)
auction.exe (TrueUpdate Client by Indigo Rose)  (74f8c7d5da1eb11e4984394b5ed83f98)

2 / 68      (PUP)
update.exe (TrueUpdate Client by Indigo Rose)  (86fa1f617111a65f4f58d8aa06467be1)

5 / 68      (PUP)
isdrcodec.exe (by goodcomms)  (ce9a40e84d04dc09ff591d234560077a)

4 / 68      (PUP)
observer.dll  (9f8fe97e7149e5c4934035d4b9870f89)

4 / 68      (PUP)
free.exe  (d86f678c21f4352a523874e4bb0c3a64)

1 / 68      (PUP)
wsgoorma.exe  (2bc0e8f12a9b79d67022cbcb4397bddc)

2 / 68      (PUP)
isgoorma.exe (by Goodcomms)  (7cd5f599d80c11ef4a9d96d755d12353)

3 / 68      (PUP)
free.exe  (04ce3eee5b3a4eea77c9a3cda846199d)

2 / 68      (PUP)
appis.exe  (60602ae63ff6681e04bb07b21678e081)

4 / 68      (PUP)
appis.exe  (fed26c2de976891bc5c8ba3c2eb7a229)

1 / 68      (PUP)
uninstall.exe  (98410efafdddfdebdcffed1405aebca5)

3 / 68      (PUP)
free.exe  (794e0c295b5bf61dba4cf57e07f6bafb)

2 / 68      (PUP)
observer.dll.voo  (fd91eaac44901f650bc715988712cd7a)

3 / 68      (PUP)
wslfilejil.exe  (9a65b8e5476abb6bae4bc962805b7d19)

3 / 68      (PUP)
isfilejil.exe (by goodcomms)  (b7e512621eb3970ad9768838f6d7d75a)

5 / 68      (PUP)
wslromancetown.exe  (6735194b6884b31cae375558d03fb656)

 
Latest 30 of 41 files

The certificates below are also signed by goodcomms Inc..

548D1AC20BFFDA165D2E423DBD29B0F2  (Dec 12, 2014 to Feb 11, 2016)

1BD77C0038E7E03D32607E6631F99C8C  (Dec 02, 2013 to Jan 02, 2015)

195A4CBA4A685695C96ED6E8C5A0EA1D  (Nov 18, 2011 to Nov 18, 2012)

Remove goodcomms Inc. Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to goodcomms Inc. by Thawte, Inc. on November 11, 2012 with the serial number '630e494ee04789e6cd2b37bb23aa30b7'.