JE communication

Publisher Information

JE communication is a software publisher located in Gangnam-gu, Seoul in Korea*. The company is a primary distributor of unwanted software. Thre are 4 additional code signing certificates issued to this publisher.
Remove JE communication Malware - Powered by Reason Core Security
Authority:
Thawte, Inc.

Valid from:
10/29/2012 9:00:00 AM

Valid to:
11/29/2013 8:59:59 AM

Subject:
CN=JE communication, OU=IT Team, O=JE communication, L=Gangnam-gu, S=SEOUL, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
79bfeddf41c2e1bd5c1c61870556a607

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.JEcommunication.K, PUP.JEcommunication.P, PUP.Service.JEcommunication.G, PUP.JEcommunication.F, PUP.JEcommunication.I, PUP.JEcommunication (M), PUP.JEcommunication.Installer (M)
100.00%

Kingsoft AntiVirus
Win32.Troj.Generic.a.(kcloud)
58.33%

Norman
FakeAV.CQZD, FakeAV.CDPR, FakeAV.CNYL, FakeAV.CLPB, FakeAV.CETG, FakeAV.BJER, FakeAV.CMBP, FakeAV.CJJI, FakeAV.CPPT, FakeAV.CETJ
44.44%

Malwarebytes
Adware.KorAd
44.44%

nProtect
Adware/W32.Agent.1147584, Adware/W32.Agent.2405384, Adware/W32.KrAdword.108152.B, Adware/W32.KrAdword.149112.B, Adware/W32.KrAdword.98864, Adware/W32.KrAdword.301688, Adware/W32.KrAdword.131320, Adware/W32.KrAdword.131904, Adware/W32.KrAdword.484984
36.11%

McAfee
Artemis!7C38FE631662, Artemis!87E11892A3EC, Artemis!117C37177E10, Artemis!562A1DEB448C, Artemis!7A8FCAFFC363, Artemis!9EE55ED39F81, Artemis!D1E75CCA709D, Artemis!5E7F185AB443
33.33%

McAfee Web Gateway
Heuristic.BehavesLike.Win32.Suspicious-PKR.O, Artemis!87E11892A3EC, Artemis!117C37177E10, Artemis!562A1DEB448C, Artemis!7A8FCAFFC363
33.33%

Dr.Web
Trojan.Adkor.31, Trojan.Adkor.195
27.78%

AhnLab V3 Security
PUP/Win32.Winerspop, Win-PUP/Helper.CloudGet.131872, Win-PUP/Helper.Winerspop.484984
22.22%

Trend Micro House Call
TROJ_GEN.F47V1104, TROJ_GEN.F47V0812, TROJ_GEN.F47V0807, Suspicious_GEN.F47V1229, TROJ_GEN.F47V0709, Suspicious_GEN.F47V0716
19.44%

1 / 68      (Adware)
lstspop.exe (Windows Explorer Lastpopup)  (6cf97fd496c82784660f2a72a8f1c51e)

1 / 68      (Adware)
lstspsp.exe (Windows Explorer Lastpopup)  (a5da2f6b302794e0bd660fe1af0e1f40)

1 / 68      (Adware)
lstspop.exe (Windows Explorer Lastpopup)  (0d9dff0d5417ffc3f425b97df752f3cc)

1 / 68      (Adware)
8_0.exe  (e6c3217f7d1ed256c1d80f8fa0595db9)

1 / 68      (Adware)
lstspsv.exe (Windows Explorer Lastpopup)  (14335047c60e50ecb496017ab3f22b76)

1 / 68      (Adware)
winspstu.exe (Windows Winerspop)  (2353ca09f0b1a6fdf79bc1730a5e9a4f)

1 / 68      (Adware)
winspst.exe (Windows Winerspop by Winerspop)  (1a570139f6cb7dac2395772f3d010cbb)

1 / 68      (Adware)
winspsp.exe (Windows Winerspop)  (0fda22145b4463c2780e5c2e3e8ab1d3)

1 / 68      (Adware)
winspep.exe (Windows Winerspop)  (bd86feb24a29f8d1e209926dbba667ef)

1 / 68      (Adware)
winspop_ezpop.exe (Windows Winerspop)  (a8fe7f7bff1033e7dd08d2d6db31a993)

1 / 68      (Adware)
winspop.exe (Windows Winerspop)  (5c326a45bf3a06dc2fdf7f2e82bb0ceb)

1 / 68      (Adware)
winspsu.EXE (Windows Winerspop)  (1c1f520096cfcf1c94925bb79beda2ba)

1 / 68      (Adware)
winspop.exe  (9bb149bf996da5ab3376fa220675775b)

1 / 68      (Adware)
isext.exe  (6a578f7890f8da238745b68281e31ff2)

1 / 68      (Adware)
winspop.exe (Windows Winerspop)  (f06e78858c6ee591419de40a59ea8a82)

8 / 68      (Adware)
uninstall.exe (Windows Winerspop)  (4afcffbb6b31cb128be1060e7d98c885)

8 / 68      (Adware)
winspop_allpopup.exe (Windows Explorer Lastpopup)  (5e7f185ab443074cc4cd1d086da4dc62)

4 / 68      (Adware)
ismsvc.exe (INSAFE Client)  (a6d7b4120ba78745b5b4a19f5f1e138d)

8 / 68      (Adware)
ISMgr.dll (INSAFE Client)  (d1e75cca709dc710d52aa54d110c0bfe)

6 / 68      (Adware)
ismsvc.exe (INSAFE Client)  (d2901b0c8b4d336a297b280a7de8d1da)

7 / 68      (Adware)
winspst.exe (Windows Winerspop by Winerspop)  (3e158e2cb156553c2894045bf9089dc8)

11 / 68    (Adware)
winspsp.exe (Windows Winerspop)  (53b546fe58055fbe97b21575dceb50e1)

6 / 68      (Adware)
winspop.exe (Windows Winerspop)  (e54c1db17e69dd17f8b4655913fd96b9)

3 / 68      (Adware)
winspep.exe (Windows Winerspop)  (e1fd79a4fbd1b15b12124ce1e92b9076)

10 / 68    (Adware)
ismsvp.exe (INSAFE Client)  (15eef3ed480dfb5687a086e41d30fa0b)

7 / 68      (Adware)
ismctrl.exe (INSAFE Client)  (cc71b146a636f0fc43a7577804377c46)

8 / 68      (Adware)
winspsv.exe (Windows Winerspop)  (9ee55ed39f81b0d4a976e81fa5d05a99)

7 / 68      (Adware)
ismsvp.exe (INSAFE Client)  (7a8fcaffc3630959c8d6d3271c542f87)

3 / 68      (Adware)
ismctrl.exe (INSAFE Client)  (04a9c248e61a60bce2314b8790b8b798)

7 / 68      (Adware)
winspstu.exe (Windows Winerspop)  (645b99007c2ed8d7f3df7f75cb289fe6)

 
Latest 30 of 36 files

The certificates below are also signed by JE communication.

40E440C0868BF76724AB0B79E1D1A63F  (Mar 26, 2014 to Mar 27, 2015)

434F5FDE34495332B10E00CB5F8397AD  (Jan 09, 2012 to Oct 17, 2012)

6AE5926AD804699F49BFF482B2BF0B53  (Aug 15, 2011 to Oct 14, 2012)

217805E59F1C39EA283584DAC5CEAD29  (Aug 30, 2010 to Aug 31, 2011)

The following publishers (by Authenticode signature organization name) are related.

Remove JE communication Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to JE communication by Thawte, Inc. on October 29, 2012 with the serial number '79bfeddf41c2e1bd5c1c61870556a607'.