MediaSave Co., Ltd.

Publisher Information

MediaSave Co., Ltd. is a software developer located in Haeundae-gu, Busan in Korea*.
Remove MediaSave Co., Ltd. Malware - Powered by Reason Core Security
Authority:
Thawte, Inc.

Valid from:
8/17/2010 9:00:00 AM

Valid to:
8/17/2012 8:59:59 AM

Subject:
CN="MediaSave Co., Ltd.", OU=EC Team, O="MediaSave Co., Ltd.", L=Haeundae-gu, S=Busan, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
5e0397df89b2f3684c31972bf965b73c

Scanner detections:
Detections  (70% detected)

Scan engine
Details
Detections

AVG
Suspicion: unknown virus, Adware Skodna.Generic.MK, Generic4, MalSign.Generic
75.00%

Reason Heuristics
PUP.MediaSaveCo.Reputation, Threat.Win.Reputation.IMP
75.00%

Comodo Security
TrojWare.Win32.Trojan.Agent.Gen, ApplicUnwnt.Win32.AdWare.Delf.D, Heur.Suspicious
50.00%

Kingsoft AntiVirus
Win32.Troj.Generic.(kcloud), Win32.Troj.Generic.a.(kcloud)
50.00%

AhnLab V3 Security
PUP/Win32.MulDown, PUP/Win32.TopUtil, PUP/Win32.Searchhost, Win-PUP/Downloader.TopUtil.1693360
50.00%

Trend Micro House Call
TROJ_GEN.F47V0723, TROJ_GEN.F47V0404, ADW_SEARCHHOST
37.50%

Dr.Web
Trojan.DownLoader6.57713, Trojan.PWS.Tibia.2231
37.50%

avast!
Win32:PUP-gen [PUP]
37.50%

Malwarebytes
Adware.Filenolja, Adware.SearchIn
37.50%

Jiangmin
Trojan/PSW.Delf.fyy, TrojanDownloader.Generic.aoyv
37.50%

0 / 68
joyutildown.exe  (fc462c382f75329544d52df4f9539abb)

0 / 68
setup_baro_bacon.exe  (1e3effb460da29b434412860c0d8198c)

5 / 68      (inconclusive)
toputilservice.exe  (88433a1f61369212f89f2b9d164dc120)

1 / 68      (Malware)
music_junk_4.0.apk.exe (Download Launcher)  (f9d9ac753974dcdebb2e1b1dc8ad1fc8)

10 / 68    (PUP)
SearchhostUpdate.exe (SearchhostUpdate by Mediasave)  (a1ed2891f6119cf42f62117a3715c729)

28 / 68    (PUP)

5 / 68      (PUP)
xnview-win-full1975.zip.exe (Download Launcher)  (f10a202ed2a960f96da069ae3b0cf30c)

4 / 68      (PUP)
toputildown.exe  (852870f915edbd453c311fa45d32ebf2)

29 / 68    (PUP)
3ivx_d4_451_win.exe (Download Launcher)  (f34f6450b5b732553d75d8d21a2a4d2a)

6 / 68      (PUP)
34984_torrenser_download.exe  (e59ad033e0ad2a9a645b815658f9f7c4)

Remove MediaSave Co., Ltd. Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to MediaSave Co., Ltd. by Thawte, Inc. on August 17, 2010 with the serial number '5e0397df89b2f3684c31972bf965b73c'.