HANcommunication

Publisher Information

HANcommunication is a software publisher located in seoul, Guro-Gu in Korea*. The company is a primary distributor of unwanted software. There is one additional code signing certificate issued to this publisher.
Remove HANcommunication Malware - Powered by Reason Core Security
Authority:
Thawte, Inc.

Valid from:
5/12/2013 9:00:00 AM

Valid to:
6/12/2015 8:59:59 AM

Subject:
CN=HANcommunication, O=HANcommunication, L=seoul, S=Guro-gu, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
3962def517f7534c2829a48f9a9454d4

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.HANcommunication.K, PUP.Installer.HANcommunication.L, PUP.BHO.HANcommunication.K, PUP.HANcommunication.I, PUP.HANcommunication.H, PUP.Hue Communication.HANcommunication (M), PUP.Hue Communication.HANcommunication.Installer (M)
100.00%

Trend Micro House Call
TROJ_GEN.F47V0407, TROJ_GEN.F47V0515, TROJ_GEN.F47V0520, TROJ_GEN.F47V0331, TROJ_GEN.F47V1022, TROJ_GEN.F47V0913, TROJ_GEN.F47V1002
41.18%

McAfee Web Gateway
Artemis!319CB2E13DB2, Heuristic.BehavesLike.Win32.Suspicious-BAY.G, Artemis!0D84DC645322, Artemis!DFEC931F107A
35.29%

ESET NOD32
Win32/AdWare.Kraddare.JP (variant), Win32/TrojanDownloader.Delf.ALM (variant), Win32/AdWare.Kraddare.KD (variant), Win32/Adware.Kraddare.DN (variant)
29.41%

MicroWorld eScan
Trojan.GenericKD.1681832, Gen:Variant.Graftor.139707, Trojan.GenericKD.1699046, Application.Generic.574202, Gen:Trojan.Heur.LP.rO9baqrjN7gO
29.41%

McAfee
Artemis!319CB2E13DB2, Artemis!F3D2A70782FF, Artemis!0D84DC645322, Artemis!44C35CA8BFC5, Artemis!DFEC931F107A
29.41%

Bitdefender
Trojan.GenericKD.1681832, Gen:Variant.Graftor.139707, Trojan.GenericKD.1699046, Application.Generic.574202, Gen:Trojan.Heur.LP.rO9baqrjN7gO
29.41%

Lavasoft Ad-Aware
Trojan.GenericKD.1681832, Gen:Variant.Graftor.139707, Trojan.GenericKD.1699046, Application.Generic.574202, Gen:Trojan.Heur.LP.rO9baqrjN7gO
29.41%

Comodo Security
ApplicUnwnt, UnclassifiedMalware
29.41%

F-Secure
Trojan.GenericKD.1681832, Gen:Variant.Graftor.139707, Trojan.GenericKD.1699046, Application.Generic.574202, Gen:Trojan.Heur.LP.rO9baqrjN7gO
29.41%

1 / 68      (Adware)
gcodecopen.exe (gcodec by HnaCommunication)  (8b23b7c96f9fe03d054cf902389aa6e8)

1 / 68      (Adware)
gcodecsetup.exe  (6003756b3b4e3c06f1709cfbd75dfec1)

1 / 68      (Adware)
GCodechper.exe  (78733ba6278d204b463e7eeb70ee7cff)

9 / 68      (Adware)
gcodecsetup.exe  (dfec931f107a4647081495ef90fcbe6f)

2 / 68      (Adware)
gcodecband.dll  (2e0a5bb32e71ce72773c2d5f6273db1c)

10 / 68    (Adware)
gcodecsl.dll (by HnaCommunication)  (c6d7aaddf85dda4be077880f8f436ba7)

5 / 68      (Adware)
GCodecuninstall.exe (by HanCommuniCation)  (cd3d47e5453e030ab595b1cdd95f4c22)

18 / 68    (Adware)
GCodechper.exe  (44c35ca8bfc5cd9773cf088ae494b4e8)

10 / 68    (Adware)
GCodecch.exe  (eccc19b02c976b2dd88c69092f87cf3a)

4 / 68      (Adware)
gcodecsl.dll (by HnaCommunication)  (63058d437f28351359349740eb42f12d)

1 / 68      (Adware)
DBGHELP.DLL (Debugging Tools for Windows by Microsoft)  (ca674f2b3670ad910ce853401c7dc204)

4 / 68      (Adware)
GCodecup.exe (by HanCommuniCation)  (eb8f24718a8bec2ebc8ef49998fa637b)

2 / 68      (Adware)
gcodecband.dll  (bd827e72b46711ab16af01c9edfcc4a3)

8 / 68      (Adware)
gcodecsetup.exe  (0d84dc64532269492d0229b2c84afd23)

7 / 68      (Adware)
gcodecopen.exe  (6c4d5bf75b3a763138bb356604b0d752)

33 / 68    (Adware)
downgcodec.exe  (f3d2a70782ff3880eef56f8308ea0cf3)

20 / 68    (Adware)
gcodecopen.exe  (bba1398ab7c4a65696c70137ca5e6fcb)

The following certificate is also signed by HANcommunication.

4DE37E21660280BEB7915BC467A96193  (May 18, 2012 to May 19, 2013)

Remove HANcommunication Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to HANcommunication by Thawte, Inc. on May 12, 2013 with the serial number '3962def517f7534c2829a48f9a9454d4'.