ISFORU Co. Ltd.

Publisher Information

ISFORU Co. Ltd. is a software developer located in Mapo-gu, Seoul in Korea*. There is one additional code signing certificate issued to this publisher.
Authority:
Thawte, Inc.

Valid from:
7/22/2010 9:00:00 AM

Valid to:
9/20/2012 8:59:59 AM

Subject:
CN=ISFORU Co. Ltd., OU=Dev Team, O=ISFORU Co. Ltd., L=Mapo-gu, S=Seoul, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
54c92ab2c9b41b853a81cad82d42f77f

Status:
Inconclusive detections from multiple engines

Scan engine
Details
Detections

Malwarebytes
Adware.KorAd, Trojan.Keylogger
77.78%

AhnLab V3 Security
PUP/Win32.MemoThis
55.56%

McAfee
Artemis!80F0447B4200, Artemis!5EAAB025F92E, Artemis!1A4A4B73D406, Artemis!4C9CE5F4D997
44.44%

Norman
NSIS_MemoThis.A, KeyLogger.IMS, Suspicious_Gen4.ABGKS, KeyLogger.HMQ
44.44%

avast!
Win32:Agent-AOIU [Trj], Win32:Agent-AOIT [Trj]
44.44%

Kaspersky
Trojan-Spy.Win32.KeyLogger, not-a-virus:AdWare.Win32.Agent
44.44%

Bitdefender
Trojan.Generic.KDV.676898, Trojan.Generic.KDV.679215, Gen:Variant.Zusy.Elzob.5888, Trojan.Agent.AUTB
44.44%

ViRobot
Trojan.Win32.A.KeyLogger.944976, Trojan.Win32.A.KeyLogger.1638024, Adware.CUPService.1995152, Adware.MemoThis.1995168.A
44.44%

Avira AntiVirus
TR/Agent.aoiu.34, Adware/Agent.ylb, TR/Agent.autb.3, TR/Agent.autb.2
44.44%

Emsisoft Anti-Malware
Trojan.Win32.Agent!IK, Adware.Win32.Agent.AMN, Gen:Variant.Zusy.Elzob.5888, Trojan.Agent.AUTB
44.44%

0 / 68
Hiverion.dll (Hiverion by IsforU Co.,Ltd)  (4d43120fb547486e6ace3eaf8a716975)

0 / 68
MemoThis.dll (MemoThis by IsforU Co.,Ltd)  (5b5b54989d0f26d1c3561cbe82c7879b)

0 / 68
Updater.exe (Updater Module)  (09a05ea62aacae72a4bfb6217cc4ea3a)

0 / 68
widget-updater-1106.exe (MemoThis by IsforU Co)  (8e630c3dd0f62128c77a45ac1f1bdea1)

0 / 68
Hiverion.dll (Hiverion by IsforU Co.,Ltd)  (152993f931c5143ed8c78ab0bf1eb247)

0 / 68
Updater.exe (Updater Module)  (7665372dc8a6a2ca591bdf6a76518a83)

0 / 68
aboki-update.exe (MemoThis by IsforU Co.)  (4d6fd8d834ce5d94f4a80614537c2d2e)

0 / 68
tomnrabbit-update.exe  (d4376a3b05c90cc626db63d909deaf94)

0 / 68
Warranty.dll  (770f4a140ff6c456c377ee75414ee553)

0 / 68
widget-updater.exe (MemoThis by IsforU Co)  (8dc19e55ce5cb38c88833f1add2a1f52)

0 / 68
MemoThis.dll (MemoThis by IsforU Co.,Ltd)  (5f760ee729c4e47310d7861c99d7c915)

0 / 68
Hiverion.dll (Hiverion by IsforU Co.,Ltd)  (46e7b027d3c0628098af92aa7711a9af)

0 / 68
aboki-update.exe  (8762ce8ea3210c36c144bdfd6b6bc016)

0 / 68
nurimom-update.exe  (02209995510ed9359206192f87c4ce57)

0 / 68
MemoThis.dll (MemoThis by IsforU Co.,Ltd)  (f92cfd07f8a4113edb59441d3be8b427)

0 / 68
Hiverion.dll (Hiverion by IsforU Co.,Ltd)  (dcfb5c04c7172ca02e4b142983954faa)

0 / 68
widget-updater-1106.exe (MemoThis by IsforU Co)  (10e0f4d92462e96d33bed1da3cf08d81)

0 / 68
gumzzi-update.exe (MemoThis by IsforU Co.)  (cb9b9f2fc37a3ef107a1c52fd715de25)

0 / 68
widget-etnews.exe (MemoThis by IsforU Co)  (d66cf95fa072a72cd20225fcbaa2c9bd)

0 / 68
memothis-update.exe (MemoThis by IsforU Co.)  (ff9564bb13024ad142bb9bcb257b3e64)

1 / 68      (inconclusive)
memothis.exe (MemoThis by IsforU Co.)  (92313c48a21d21d4778d21b59d37bb3f)

27 / 68    (PUP)
mal_3.exe (MemoThis by IsforU Co.)  (4c9ce5f4d99760b417bf4c882327635d)

29 / 68    (PUP)
mal_2.exe (MemoThis by IsforU Co.)  (1a4a4b73d406dc50fc0db16f422c3a46)

23 / 68    (PUP)
malware_245.exe (MemoThis by IsforU Co)  (5eaab025f92eaa62a55b43a031227cb7)

19 / 68    (PUP)
malware_032.exe (MemoThis by IsforU Co.)  (80f0447b4200c1dd1ef626962daf44dd)

1 / 68      (inconclusive)
Hiverion.dll (Hiverion by IsforU Co.,Ltd)  (0446d1d4b7e3cb6b6178e4ec50520de7)

1 / 68      (inconclusive)
MemoThis.dll (MemoThis by IsforU Co.,Ltd)  (9cfb500faeaa156e79eb8c5bb2c5cc68)

2 / 68      (inconclusive)
Updater.exe (Updater Module)  (78b515df5a8b1c3c813e7f5c0fb6f6ea)

The following certificate is also signed by ISFORU Co. Ltd..

5EC0C91AD09C7D0D8D80F5E4456A0106  (Sep 12, 2012 to Oct 13, 2014)

* Note, the details and description above are based on the code signing digital signature issued to ISFORU Co. Ltd. by Thawte, Inc. on July 22, 2010 with the serial number '54c92ab2c9b41b853a81cad82d42f77f'.