JE communication

Publisher Information

JE communication is a software publisher located in Gangnam-gu, Seoul in Korea*. The company is a primary distributor of unwanted software. Thre are 4 additional code signing certificates issued to this publisher.
Authority:
Thawte, Inc.

Valid from:
3/26/2014 9:00:00 AM

Valid to:
3/27/2015 8:59:59 AM

Subject:
CN=JE communication, OU=IT Team, O=JE communication, L=Gangnam-gu, S=SEOUL, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
40e440c0868bf76724ab0b79e1d1a63f

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Service.JEcommunication.H, PUP.JEcommunication.H, PUP.JEcommunication (M), PUP.JEcommunication.Installer (M), PUP.JEcommun (M), PUP.JEcommun.Installer (M), PUP (M)
100.00%

AVG
Generic
21.43%

Malwarebytes
Adware.KorAd
17.86%

Trend Micro House Call
TROJ_GEN.F47V0418, TROJ_GEN.F47V0417, Suspicious_GEN.F47V0208, Suspicious_GEN.F47V0202
17.86%

AhnLab V3 Security
PUP/Win32.Winerspop, PUP/Win32.savepop
17.86%

Norman
FakeAV.CTNW, FakeAV.CTOF, FakeAV.CUYW, FakeAV.CUYE
14.29%

McAfee
Artemis!06173447F484, Artemis!7D2E728B8661, Artemis!A522E3DA3D00, Artemis!2E6169ABF59B
14.29%

Dr.Web
Trojan.Adkor.31, Trojan.Adkor.63
14.29%

Bkav FE
W32.HfsAdware
10.71%

IKARUS anti.virus
Trojan.SuspectCRC
3.57%

1 / 68      (Adware)

1 / 68      (Adware)
winspstu.exe (Windows Winerspop)  (211bb46abfb74196c37f52a6491f89b3)

1 / 68      (Adware)

1 / 68      (Adware)
savekakao_v20150216.exe  (7fb57da6f97b31ab9816eb91538009e8)

1 / 68      (Adware)
savekakao.EXE  (ea0f44ca91a996db213e813062952cd2)

1 / 68      (Adware)
savekakaoUpdate.EXE  (9352e22454cd85646c9d58cb2efee0b5)

1 / 68      (Adware)

1 / 68      (Adware)
setup_popnpop.exe  (c784e155b9b2fa6b1592d9cc5288ce1e)

1 / 68      (Adware)
winspsu.EXE (Windows Winerspop)  (d5b2d83b7efd567c4215eee85a050805)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
setup_songple player_exe  (a4e748c767caa79bda7f6999de6abf10)

1 / 68      (Adware)
songplecnt.exe  (fa85fd0229b3aaa85487f391f81aed95)

1 / 68      (Adware)
Songple.EXE (Songple)  (24a7b5c1eb63fe206550a875a99de37a)

1 / 68      (Adware)

1 / 68      (Adware)
DualVaccine.exe (DualVaccine)  (dc55003a8aa4adee217feafac34eedbd)

4 / 68      (Adware)

4 / 68      (Adware)

7 / 68      (Adware)

6 / 68      (Adware)

6 / 68      (Adware)

3 / 68      (Adware)

1 / 68      (Adware)

4 / 68      (Adware)
winspst.exe (Windows Winerspop by Winerspop)  (f572abcd7a532ca480800f29614319fc)

7 / 68      (Adware)
winspsp.exe (Windows Winerspop)  (06173447f48496beb66b6414963b632e)

2 / 68      (Adware)
winspop.exe (Windows Winerspop)  (9ec137d10428462dbb9b9850967583f4)

4 / 68      (Adware)
winspep.exe (Windows Winerspop)  (7462f563173ad047623ab861341aaa60)

4 / 68      (Adware)
winspsv.exe (Windows Winerspop)  (ce0f9ff9e56efe6e1bfc4d43c9fd930c)

The certificates below are also signed by JE communication.

79BFEDDF41C2E1BD5C1C61870556A607  (Oct 29, 2012 to Nov 29, 2013)

434F5FDE34495332B10E00CB5F8397AD  (Jan 09, 2012 to Oct 17, 2012)

6AE5926AD804699F49BFF482B2BF0B53  (Aug 15, 2011 to Oct 14, 2012)

217805E59F1C39EA283584DAC5CEAD29  (Aug 30, 2010 to Aug 31, 2011)

The following publishers (by Authenticode signature organization name) are related.

* Note, the details and description above are based on the code signing digital signature issued to JE communication by Thawte, Inc. on March 26, 2014 with the serial number '40e440c0868bf76724ab0b79e1d1a63f'.