Halo Share Technology Co., Ltd.

Publisher Information

Halo Share Technology Co., Ltd. is a software developer located in Chengdu, Sichuan in China*. The publisher primarily developes software that can be classified as adware.
Authority:
WoSign CA Limited

Valid from:
8/21/2014 3:13:16 PM

Valid to:
9/21/2015 3:13:16 PM

Subject:
CN="Halo Share Technology Co., Ltd.", E=haloshare@foxmail.com, O="Halo Share Technology Co., Ltd.", L=Chengdu, S=Sichuan, C=CN

Issuer:
CN=WoSign Class 3 Code Signing CA, O=WoSign CA Limited, C=CN

Serial number:
38b5165a38a245cf4db8c8b8b67c896e

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.HaloShareTechnologyCo, PUP.HaloShareTechnologyCo, PUP.Service.HaloShareTechnologyCo, PUP.Startup.HaloShareTechnologyCo, PUP.HaloShar.Installer
100.00%

Qihoo 360 Security
Win32/Trojan.f25, Win32/Trojan.Adware.37e, Win32/Trojan.67a
52.38%

AVG
Found Win32/DH{gRIPEx4UTxUb}, Generic5, Win32/DH{gRKBEyAkWAASZBMiDzUnKIEQ}, Found Win32/DH{gRKBEyAkWAASZBMiDzUnKH6BEGc}
26.19%

IKARUS anti.virus
Win32.SuspectCrc, PUA.Zmrili
23.81%

Vba32 AntiVirus
BScope.Trojan-Dropper.Inject, suspected of Trojan.Downloader.gen.h
16.67%

ESET NOD32
Win32/AdWare.Zmrili (variant), Win32/DllInject.BY (variant)
16.67%

Kaspersky
HEUR:Trojan.Win32.Invader
14.29%

Avira AntiVirus
TR/Agentbypass.G.478, TR/Agentbypass.G.483, TR/Agentbypass.G.484, TR/Dropper.Gen
14.29%

McAfee
Artemis!9C2F80B7A30F, Artemis!BA3BB5F04CB5, Artemis!275F894DB0B4, Artemis!FC4F21CC3B41
9.52%

Microsoft Security Essentials
Threat.Undefined, Trojan:Win32/AgentBypass.gen!G
7.14%

1 / 68      (PUP)
bootime7.sys  (e09e892a8681bfbfad962c71e49de7cf)

1 / 68      (PUP)
setup_rili.exe (Setup Module)  (30e4e2c32e900f61633d418020182963)

1 / 68      (PUP)
zmplatform.exe (zmplatform)  (82a90ddeacb3c5399889d21b0c86991d)

1 / 68      (PUP)
bootime7.sys  (14027e80d97a68969387cf8a97037c94)

1 / 68      (PUP)
zmplatform.exe (zmplatform)  (403975facfac9a3bfef449017f54dee3)

1 / 68      (PUP)
setup_rili.exe  (a38be98728c2d367f1e2e079b0f326e3)

1 / 68      (PUP)
bootime7.sys  (70e97ec271d5a9449b77f5ca438d1e76)

1 / 68      (PUP)
bootime7.sys  (91ac67279c5c90cfd5c5a649289d3763)

1 / 68      (PUP)
setup_rili.exe (Setup Module)  (68d7f51ae3862b736b35e70ffb02a78b)

1 / 68      (PUP)
zmplatform.exe (zmplatform)  (56283224f5e2f39ade103a3f8479282b)

1 / 68      (PUP)
zmplatform.exe (zmplatform)  (f05ccf10ae6110fbb11f0190be1035cf)

1 / 68      (PUP)
setup_rili.exe (Setup Module)  (ec21116f1854f308d0e02195feeaacff)

1 / 68      (PUP)
dwh3e80.exe (Setup Module)  (4ad2905b5385eef1d3c9df18401489b2)

1 / 68      (PUP)
bootime7.sys  (bb97017fc16684bc1e7bbcccaf66a9e1)

1 / 68      (PUP)
bootime7.sys  (9785fa3f9d8ee07f5ec20c87bc7b3775)

1 / 68      (PUP)
wonarp.sys  (2ca5903480dbcf61c5bf3ac1701aa4a6)

6 / 68      (PUP)
zmplatform.exe (zmplatform)  (50c32f2bb03d2221b3b3eb0c4e47dff5)

3 / 68      (PUP)
bootime7.sys  (17e8bef8f7f2a4e4ff4c598c81fb2b24)

23 / 68    (PUP)
zmrili.exe (Rili Module)  (fc4f21cc3b41fd9ffa42a8d94f643b51)

3 / 68      (PUP)
bootime7.sys  (5d9cb57b586eba5e1f57d33c60b4d562)

2 / 68      (PUP)
bootime7.sys  (44c26f1604318f170fa76315dd5221cd)

2 / 68      (PUP)
bootime7.sys  (a957d4e563d921cb2ab7773bbe3c12b0)

2 / 68      (PUP)
bootime7.sys  (412e623c3afb976ed635d239b1b731ec)

23 / 68    (PUP)
zmplatform.exe (zmplatform)  (275f894db0b4fc7cccfe1ef48436feb2)

3 / 68      (PUP)
zmplatform.exe (zmplatform)  (1e0348b40fe30a26753f2fd7dcd5ba7b)

3 / 68      (PUP)
bootime7.sys  (be04248c7c49dabe50acc940c32d9492)

5 / 68      (PUP)
zmplatform.exe (zmplatform)  (4b1d09cc1fe02487ed43d36aad0d7b24)

2 / 68      (PUP)
NDuilib.dll  (c9fa25e47bdd3eca34689ee286eddbb3)

2 / 68      (PUP)
Inject64.exe  (a633d74c1f8544ab22018886ef4b613b)

2 / 68      (PUP)
Helper.dll  (022d81d1e990ffea1aa7b7d26d97894f)

 
Latest 30 of 42 files

* Note, the details and description above are based on the code signing digital signature issued to Halo Share Technology Co., Ltd. by WoSign CA Limited on August 21, 2014 with the serial number '38b5165a38a245cf4db8c8b8b67c896e'.