JE communication

Publisher Information

JE communication is a software publisher located in Gangnam-gu, Seoul in Korea*. The company is a primary distributor of unwanted software. Thre are 4 additional code signing certificates issued to this publisher.
Authority:
Thawte, Inc.

Valid from:
10/29/2012 9:00:00 AM

Valid to:
11/29/2013 8:59:59 AM

Subject:
CN=JE communication, OU=IT Team, O=JE communication, L=Gangnam-gu, S=SEOUL, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
79bfeddf41c2e1bd5c1c61870556a607

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.JEcommunication (M), PUP.JEcommunication.Installer (M), PUP.JEcommun (M), PUP.JEcommun.Installer (M), PUP (M)
100.00%

Kingsoft AntiVirus
Win32.Troj.Generic.a.(kcloud)
16.00%

Malwarebytes
Adware.KorAd
14.00%

Norman
FakeAV.CETJ, FakeAV.CETK, FakeAV.BUPQ, FakeAV.BUPS, FakeAV.BWDG, FakeAV.BVFK
12.00%

Dr.Web
Trojan.Adkor.195, Trojan.Adkor.31
8.00%

AhnLab V3 Security
PUP/Win32.Winerspop, Win-PUP/Helper.CloudGet.131872, Win-PUP/Helper.Winerspop.484984
8.00%

nProtect
Adware/W32.KrAdword.131904, Adware/W32.KrAdword.484984, Adware/W32.KrAdword.108152, Adware/W32.KrAdword.108152.B
8.00%

McAfee
Artemis!53B546FE5805, Artemis!D1E75CCA709D, Artemis!5E7F185AB443, Artemis!4AFCFFBB6B31
8.00%

McAfee Web Gateway
Artemis!53B546FE5805
8.00%

Trend Micro House Call
TROJ_GEN.F47V0709, Suspicious_GEN.F47V0716, Suspicious_GEN.F47V0815
6.00%

1 / 68      (Adware)
winspep.exe (Windows Winerspop)  (27071339ea325246e0002d671418e381)

1 / 68      (Adware)
winspop_runpart.exe  (fdbb25c8886d21212c3ea369d251a484)

1 / 68      (Adware)
vaccinetek_power.exe  (8eaee0cf4952c1a5107dd31d843e7c99)

1 / 68      (Adware)
vaccinetek_live.exe  (a2956b20ed9d40070914170ba4b96c11)

1 / 68      (Adware)
winspep.exe (Windows Winerspop)  (00e77e99df7ac9c1f3d2f0623d9f4365)

1 / 68      (Adware)
8_-1.exe  (e22dd215da443cb8d46dbe77495a710b)

1 / 68      (Adware)
lstspop.exe (Windows Explorer Lastpopup)  (8522fb3f1b8f0f71cb3dc1c8c9acdf6e)

1 / 68      (Adware)
winspep.exe (Windows Winerspop)  (ccb6260ed2e68eaaed754290294b5353)

1 / 68      (Adware)
winspsv.exe (Windows Winerspop)  (2256cd84a7b3ae1206c35638c3c93297)

1 / 68      (Adware)
winspsv.exe (Windows Winerspop)  (c92f2ad62f807a3c129e49d435182028)

1 / 68      (Adware)
winspsp.exe (Windows Winerspop)  (c624344734ffc76a74f9d8b6c2f77e31)

1 / 68      (Adware)
winspop.exe  (e72d65d6d17b5c9a3a424bff599ecd5a)

1 / 68      (Adware)
winspep.exe (Windows Winerspop)  (bf243accea3a9944a86978b14fa0ec13)

1 / 68      (Adware)
winspsv.exe (Windows Winerspop)  (40cd5aad1a7cc332a62136130576a44c)

1 / 68      (Adware)
winspop.exe (Windows Winerspop)  (351cec7786095c97c9fb48c1f44a9f71)

1 / 68      (Adware)
winspsp.exe (Windows Winerspop)  (9f687e53662a4c19816b8dd32bbbe761)

1 / 68      (Adware)
uninstall.exe (Windows Winerspop)  (9a403ae3a2d7f8f008a1d385569430fc)

1 / 68      (Adware)
winspsv.exe (Windows Winerspop)  (94516139bb3477f58953f0926c4bccf1)

1 / 68      (Adware)
lstspop.exe (Windows Explorer Lastpopup)  (de4d3596d7259cd92809e5dcbdaa27f4)

1 / 68      (Adware)
setup_self.exe (INSAFE Client)  (4886c3a3d979dd8045ab93737a948e95)

1 / 68      (Adware)
lstspsv.exe (Windows Explorer Lastpopup)  (ac063d72d4322382f1d2f98dc9b2a47e)

1 / 68      (Adware)
setup_tang.exe (INSAFE Client)  (8b1d2ea6857f08ae7b153bf2b05530b0)

1 / 68      (Adware)
setup_pang.exe (Windows Explorer Lastpopup)  (5e7823ea5674620bf228807afdd14370)

1 / 68      (Adware)
lstspsp.exe (Windows Explorer Lastpopup)  (b875e2b462823e08cd6e60acff5913f9)

1 / 68      (Adware)
lstspop.exe (Windows Explorer Lastpopup)  (4c2684d70b559aecff41696f82b2efab)

1 / 68      (Adware)
ISMgr.dll (INSAFE Client)  (fd683f328afd125eb0979a7c966c0387)

1 / 68      (Adware)
ismctrl.exe (INSAFE Client)  (202225b51314130bf67af285bdbb1a38)

1 / 68      (Adware)
lstspop.exe (Windows Explorer Lastpopup)  (6cf97fd496c82784660f2a72a8f1c51e)

1 / 68      (Adware)
lstspsp.exe (Windows Explorer Lastpopup)  (a5da2f6b302794e0bd660fe1af0e1f40)

1 / 68      (Adware)
lstspop.exe (Windows Explorer Lastpopup)  (0d9dff0d5417ffc3f425b97df752f3cc)

 
Latest 30 of 63 files

The certificates below are also signed by JE communication.

40E440C0868BF76724AB0B79E1D1A63F  (Mar 26, 2014 to Mar 27, 2015)

434F5FDE34495332B10E00CB5F8397AD  (Jan 09, 2012 to Oct 17, 2012)

6AE5926AD804699F49BFF482B2BF0B53  (Aug 15, 2011 to Oct 14, 2012)

217805E59F1C39EA283584DAC5CEAD29  (Aug 30, 2010 to Aug 31, 2011)

The following publishers (by Authenticode signature organization name) are related.

* Note, the details and description above are based on the code signing digital signature issued to JE communication by Thawte, Inc. on October 29, 2012 with the serial number '79bfeddf41c2e1bd5c1c61870556a607'.