HOW SOFT

Publisher Information

HOW SOFT is a software publisher located in Guro-gu, Seoul in Korea*. The publisher primarily developes software that can be classified as adware. Thre are 2 additional code signing certificates issued to this publisher.
Remove HOW SOFT Malware - Powered by Reason Core Security
Authority:
Thawte, Inc.

Valid from:
11/29/2011 9:00:00 AM

Valid to:
1/28/2013 8:59:59 AM

Subject:
CN=HOW SOFT, O=HOW SOFT, L=Guro-gu, S=SEOUL, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
567c8147e85208efce0495c1d8ac015f

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.HOWSOFT.I, PUP.HOWSOFT.T, PUP.HOWSOFT.R, PUP.HOWSOFT.D, PUP.HOWSOFT.J, PUP.Installer.HOWSOFT.R, PUP.Hue Communication, PUP.Hue Communication.HOWSOFT (M), PUP.Hue Communication.HOWSOFT.Installer (M)
100.00%

AVG
MalSign.Generic, Suspicion: unknown virus, Generic5, Downloader.AKH.dropper
63.41%

avast!
Win32:HowSoft-A [PUP], Win32:PUP-gen [PUP], Win32:Installer-AA [PUP]
51.22%

Malwarebytes
Adware.K.WindowSearch, PUP.K.OpenTab, Adware.KorAd, Adware.Kraddare, Adware.Agent
43.90%

AhnLab V3 Security
PUP/Win32.WindowSearch, PUP/Win32.OpenSearch, Win-PUP/Helper.OpenSearch.99920, Win-PUP/Player.Howcodec.342096.B, Win-PUP/Player.HowCodec.303696
34.15%

McAfee Web Gateway
Heuristic.BehavesLike.Win32.ModifiedUPX.C!86, Heuristic.BehavesLike.Win32.Suspicious-BAY.G, Artemis!94CD98F644A0, Artemis!7E80EA99ED44
24.39%

Trend Micro House Call
TROJ_GEN.F47V0723, TROJ_GEN.F47V0802, TROJ_GEN.F47V0729, ADW_WSEARCH, TROJ_GEN.RCBH1C9, TROJ_GEN.RCBH2B2, TROJ_GEN.RCBZ1KT
21.95%

K7 AntiVirus
Riskware , Adware , Trojan, Trojan , Virus
14.63%

VIPRE Antivirus
Trojan.Win32.Generic
14.63%

Bkav FE
W32.Clod38b.Trojan, W32.HowCodecLnrAB.Trojan, W32.FakeCodecAAE.Trojan, HW32.CDB
12.20%

1 / 68      (PUP)
Down_LoadGetupHp.exe  (6f10f7fbdff4b09e31b635f2d3d89499)

1 / 68      (PUP)
Down_LoadGetUpgrade.exe  (399cccdcd9f00f345a733e4cb7ff4d2c)

1 / 68      (PUP)
HowCodecSvc.exe (by HowSoft)  (f45b847134152b24811b56f21b486cf6)

1 / 68      (PUP)
hka.dll (hka.dll by HowSoft)  (593b93688462120233852cc6404c12c8)

1 / 68      (PUP)
howcodecsetup.exe  (0c7c43a509e425fcebc414067a4f2e15)

1 / 68      (PUP)
kth_opensearch_fsetup.exe  (0939fbfc1b46256c37b46e27befe7dd8)

1 / 68      (PUP)
howcodechper.exe (howcodec by HowSoft)  (bd63f962aff1ecd81e3d2a5e29c98edb)

1 / 68      (PUP)
kos_guide.dll (by HowSoft)  (b288e372393a8bec40189d2d6b5e0b2f)

1 / 68      (PUP)
downloadgetinstall.exe  (a23a26cf6e05af2a032200dc9451b405)

1 / 68      (PUP)

1 / 68      (PUP)
howcodec_unins.exe (by HowSoft)  (474337028719c86e23495bf90be7756b)

1 / 68      (PUP)
HowcodecOpen.exe (HowcodecOpen by HowSoft)  (a8183555d358be5aadfba026aa45e6da)

11 / 68    (PUP)
DownLoadGet.exe  (7f10cc27375e9ce0405be370b3d4e681)

3 / 68      (PUP)
DownLoadDownAgree.exe  (36a418a330200b9233027c989e968bcb)

2 / 68      (PUP)

21 / 68    (PUP)
DownLoadGetInstall.exe  (5366475029d3bf40a4404dee30a97209)

2 / 68      (PUP)

3 / 68      (PUP)
timeAdd.dll  (cc2f30e63f96f55ae7271284878db732)

11 / 68    (PUP)
howcodec_update.exe (by HowSoft)  (ed46a376f0e97125b87897c921b2bd4b)

6 / 68      (PUP)
howcodec_unins.exe (howcodec uninstall by howsoft)  (00b0ab83670289ebad4fada0bbb593de)

11 / 68    (PUP)
HowcodecOpen.exe (HowcodecOpen by HowSoft)  (a14db31a99fc7b6bff69b4b6ff9903ed)

8 / 68      (PUP)
hka.dll (hka.dll by HowSoft)  (96b6041af7db90b74e4c6cb0c83d80cb)

8 / 68      (PUP)
wsact.dll (WindowSearch BHO by HowSoft)  (8cc32293529c1bb42930a73059d661b4)

29 / 68    (PUP)
howcodecsrv.exe  (7e80ea99ed4437159e9e94fc05153443)

8 / 68      (PUP)
downloadgetsvc.exe (by HowSoft)  (252fcbf4336a1e16b9dd4051aed54e6c)

10 / 68    (PUP)
wssvrch.exe (by HowSoft)  (94cd98f644a023ec408ca3fd5af4cba2)

8 / 68      (PUP)
wsstart.exe (WindowSearch Version Manager by HowSoft)  (6ae825027f0769caafcbb1aa8d40cc05)

14 / 68    (PUP)
wssvrelv.exe (WindowSearch Service Manager by HowSoft)  (dd744087c0b06b7c8e97e91e03b75bbe)

6 / 68      (PUP)
howcodec_update.exe (by HowSoft)  (2c4e14b64fedb7b17229b9bedd34bee9)

4 / 68      (PUP)
howcodec_unins.exe (by HowSoft)  (07ab90e0223b9bda1b7d33c1ad644010)

 
Latest 30 of 41 files

The certificates below are also signed by HOW SOFT.

7BA3F775C5D05768F56F97039538592C  (Jan 30, 2013 to Mar 02, 2015)

3B9817FBE154B0346689E1852F9704A7  (Dec 16, 2010 to Dec 17, 2011)

Remove HOW SOFT Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to HOW SOFT by Thawte, Inc. on November 29, 2011 with the serial number '567c8147e85208efce0495c1d8ac015f'.