Now Media Corp.

Publisher Information

Now Media Corp. is a software developer located in Uijeongbu-si, Gyeonggi-Do in Korea*. Software developed by Now Media Corp. has been typically classified as potentially unwanted software. Thre are 4 additional code signing certificates issued to this publisher.
Remove Now Media Corp. Malware - Powered by Reason Core Security
Authority:
Thawte, Inc.

Valid from:
3/24/2012 9:00:00 AM

Valid to:
4/24/2013 8:59:59 AM

Subject:
CN=Now Media Corp., OU=EC Team, O=Now Media Corp., L=Uijeongbu-si, S=Gyeonggi-do, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
3acfbf44aa68ca08512b1ba9c041d893

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Optional.NowMediaCorp.G, PUP.Optional.NowMediaCorp.H, PUP.Optional.NowMediaCorp.g, Win32.Generic.NowMediaCorp.Meta, Win32.Generic.Installer.Meta
100.00%

Malwarebytes
Adware.Korad, Adware.Kraddare, Adware.K.WinKM, Adware.WindowAssist.K, Adware.KorAd
40.91%

Comodo Security
UnclassifiedMalware, ApplicUnwnt, Heur.Suspicious
40.91%

ESET NOD32
Win32/Adware.Kraddare.FR, Win32/Adware.Kraddare.HD (variant), Win32/Adware.Kraddare.EQ (variant), Win32/AdWare.Kraddare.IM (variant)
36.36%

McAfee
Artemis!01FBEAE20892, Artemis!347206086023, Artemis!43FBBA697777, Artemis!3AA7388DC35D, Artemis!9D931EE9A2B0, Artemis!99919B70543C
27.27%

VIPRE Antivirus
SearchIt Toolbar, Trojan.Win32.Generic, Trojan.Win32.Generic!SB.0
22.73%

McAfee Web Gateway
Artemis!01FBEAE20892, Artemis!347206086023, Artemis!43FBBA697777, Artemis!99919B70543C
22.73%

Trend Micro House Call
TROJ_GEN.RCBH1HO, Suspicious_GEN.F47V1025, Suspicious_GEN.F47V1112, ADW_KRADDARE, Suspicious_GEN.F47V1016
22.73%

AVG
Generic5, Skodna.Generic
18.18%

nProtect
Adware/W32.Agent.367232, Adware/W32.Agent.98880, Adware/W32.Agent.305352
13.64%

1 / 68      (PUP)
winkmc.dll (Windows Key Manager)  (17a3c0e94f6f6b5e2f703c127e71ab54)

1 / 68      (PUP)
winkpku.exe (Windows Key Pack)  (de5bac423b6ac9fb768bffb40ea30708)

1 / 68      (PUP)
winkpkc.dll (Windows Key Pack)  (26ce704688471ee266e430593026e3dc)

1 / 68      (PUP)
winkpkv.exe (Windows Key Pack)  (13ba631318ca2a420bc55e1c9021451c)

5 / 68      (PUP)
pre_clude.exe (Windows CloudGet)  (cb73c84faba4e941995fc326b3970c2f)

5 / 68      (PUP)
winasu.exe (Windows Assist)  (02e5a8198eb0b5cf0f9b7356285495fb)

9 / 68      (PUP)
winkmu.exe (Windows Key Manager)  (efa0d6940285d28ab7a5dbabfdb2d312)

1 / 68      (PUP)
mmupdate.exe (Windows Multimedialab by Multimedialab)  (e61132911ca8d3c48c7b05e652fa43dd)

1 / 68      (PUP)
mmclt.exe (Windows Multimedialab by Multimedialab)  (2be4ae942046339593f7248b758502ea)

1 / 68      (PUP)
mmcfg.exe (Windows Multimedialab)  (b993eb7b0319cab4ba800317740b7a49)

3 / 68      (PUP)
winasu.exe (Windows Assist)  (a0842b398e612028f1ad4cec4cea138e)

18 / 68    (PUP)
winasv.exe (Windows Assist Service)  (99919b70543ccae9abb38f89ac652b2c)

12 / 68    (PUP)
winkmv.exe (Windows Key Manager)  (9d931ee9a2b0acd5b52e19bcfda7b641)

7 / 68      (PUP)
mmsvc.exe (Windows Multimedialab by Multimedialab)  (3aa7388dc35d1a4b4b23d8ac8dd7fd49)

1 / 68      (PUP)
smpsvp.exe (Windows Smart Pack)  (a92421167cfa418bed6bed1dee3c3c85)

13 / 68    (PUP)
smartmanager.exe  (43fbba6977773c39829b92c89489baff)

1 / 68      (PUP)
smpsvc.exe (Windows Smart Pack)  (8f8e1004162ca9f622a03b2e3f02aed1)

11 / 68    (PUP)
smpsvu.EXE (Windows Smart Pack)  (347206086023e9a5424e46bcc30df9f4)

13 / 68    (PUP)

3 / 68      (PUP)
smpsvtu.exe (Windows Smart Pack)  (5cf68d311c9bf87dab3557a7a55baa9a)

2 / 68      (PUP)
Camnori.exe  (93230f802bbba06e0f5c289e8017ffa9)

4 / 68      (PUP)
smpsvt.exe (Windows Smart Pack)  (3687d4306a9486a9f346271c11408ca0)

The certificates below are also signed by Now Media Corp..

7883D9D5206A6138CFE83DE378370E66  (Jun 10, 2015 to Jul 10, 2016)

25C372720A2798CEC8A2BEB593A4175F  (May 16, 2014 to Jun 16, 2015)

749F0C73DD0E02A17770A43633F7EB21  (Apr 23, 2013 to May 24, 2014)

29D5DBAF891AA1034589D2F65DC9286A  (Mar 21, 2011 to Mar 21, 2012)

The following publishers (by Authenticode signature organization name) are related.

Remove Now Media Corp. Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to Now Media Corp. by Thawte, Inc. on March 24, 2012 with the serial number '3acfbf44aa68ca08512b1ba9c041d893'.