TGSM Inc.

Publisher Information

TGSM Inc. is a software developer located in Haeundae-gu, Busan in Korea*. The company is a primary distributor of unwanted software. Thre are 4 additional code signing certificates issued to this publisher.
Remove TGSM Inc. Malware - Powered by Reason Core Security
Authority:
Thawte, Inc.

Valid from:
2/11/2011 9:00:00 AM

Valid to:
3/13/2012 8:59:59 AM

Subject:
CN=TGSM Inc., OU=Dev Team, O=TGSM Inc., L=Haeundae-gu, S=Busan, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
5110a6616204b0264e74f3527fa2aa76

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.TGSM.L, PUP.Installer.TGSM.F, PUP.TGSM.J, PUP.TGSM.G, PUP.TGSM.N, PUP.TGSM.K, PUP.TGSM (M), PUP.TGSM.Installer (M), PUP.OpenShopper.TGSM (M), PUP.OpenShopper.TGSM.Installer (M)
100.00%

AVG
OpenShopper.A, Generic4, Skodna.Generic_r.I, Adware OpenShopper.A
72.97%

Dr.Web
Adware.OpenShopper.3, Adware.OpenShopper.3, Trojan.Adkor.340
54.05%

Clam AntiVirus
Adware.Openshopper-2, Adware.Openshopper-3
40.54%

ESET NOD32
Win32/Adware.OpenShopper (variant), Win32/Adware.Kraddare.AX (variant)
35.14%

Trend Micro House Call
TROJ_GEN.RCBH1KE, TROJ_GEN.F47V1011, TROJ_GEN.RCBH1GP, TROJ_GEN.F47V1008, TROJ_GEN.F47V0810, TROJ_GEN.R06H1GB, TROJ_GEN.F47V0809
29.73%

avast!
Win32:PUP-gen [PUP], Win32:OpenShopper-A [PUP], Win32:Tgsm-B [PUP]
29.73%

IKARUS anti.virus
Win32.SuspectCrc, OpenShopper, Trojan.Win32.Kryptik.EI, AdWare.Win32.OpenShopper, Application.AdWare.POV
29.73%

Avira AntiVirus
Adware/Kraddare.B.16, Adware/Adware.389912, Adware/Kraddare.AX.3, ADWARE/Adware.Gen, TR/Kryptik.EI.1, ADWARE/OpenShopper.D.21
27.03%

McAfee
Artemis!9F738E980EB3, Artemis!FC1936E584C8, Artemis!2E9054E5EF36, Artemis!6664D5916A41, Artemis!117DBBCEBBB1, Artemis!5378EE4214FC
24.32%

25 / 68    (Adware)
setup.exe (by http://sharebox.co.kr)  (fccd8ec578f6ff1c6e93b83ab397bd4d)

1 / 68      (Adware)
regdel.exe (OpenShopper Pre Uninstaller by TGSM)  (d9b23fe1329efb1daad0e95d564cbae2)

1 / 68      (Adware)
JJangQSearchBarU.exe (JJangQSearchBarU by TGSM)  (71d877466c7d169c0c859c911bde3866)

1 / 68      (Adware)
DsSearchBarU.exe (DsSearchBarU by TGSM)  (abd290817d46551a91589c79af18cc21)

25 / 68    (Adware)
setup.exe (by http://sharebox.co.kr)  (8fee0dd2184dfb037a2fe3c742c1c1b2)

1 / 68      (Adware)
54210.exe  (16d7fd8961ce27236c2a29119024e062)

1 / 68      (Adware)
setup.exe (by http://jjangq.co.kr)  (440b7be1573a6ec9d980d91a657ca29d)

6 / 68      (Adware)
bboxsupdate.exe (by http://openshopper.co.kr)  (de4a0c420a3c135595bcc50a0be54560)

1 / 68      (Adware)
setup.exe (by http://sharebox.co.kr)  (5f83375aba003a71b8d58f6003d4706a)

1 / 68      (Adware)
okextern.exe (by http://openkeyword.co.kr)  (38f2efa2d40ff3acf0c57cb4b59a250e)

1 / 68      (Adware)
35046.exe (by http://openkeyword.co.kr)  (014e7b9e26e3ea70cde77c39f790cc0c)

1 / 68      (Adware)
17469296.exe (by http://openkeyword.co.kr)  (5d47b4790e0dc20d953a8ce90fe2ad25)

17 / 68    (Adware)
setup.exe (by http://jjangq.co.kr)  (0d5aef58ceb96b66e95e862b498cc99b)

4 / 68      (Adware)
SBoxSearchBarHK.dll (SBoxSearchBarHK by MONE)  (314c9aec80ab96afafcb95c38364b294)

6 / 68      (Adware)
SBoxSearchBar.exe (SBoxSearchBar by TGSM)  (6eec546df2303b2594a0b3b47ee1f96d)

16 / 68    (Adware)
SBoxSearchBarU.exe (SBoxSearchBarU by TGSM)  (3327544030cad9c30d1a2900f8fb1fe5)

5 / 68      (Adware)
ShareBoxCtrl.dll (ShareBoxCtrl by TGSM)  (6f333f1d5bdd671eabe003968baf3020)

7 / 68      (Adware)
ShareBoxC.exe (SHAREBOX by TGSM)  (df67f334de8effcc64db369d67c6cf6b)

3 / 68      (Adware)

2 / 68      (Adware)
nat.dll (by interhouse Inc)  (071a3af82828c96f6cb7a71ae65d4498)

4 / 68      (Adware)
JJangQUp.exe (by TGSM)  (88cf8556a7083f9baf2939c1718261fa)

3 / 68      (Adware)
jjangqdown2.exe (by TGSM)  (7c0c90277361bbc5dd4aaee9c3abf79c)

3 / 68      (Adware)
JJangQDown.exe (by TGSM)  (d6d143c9b733bcbf0d31230a720a78de)

11 / 68    (Adware)
JJangQC.exe (JJANGQ UPDATE by TGSM)  (66e0843cf936b1826153cf348d074760)

12 / 68    (Adware)
stextern_f.exe (by http://smarttip.co.kr)  (117dbbcebbb1d84759731499c587c0f1)

21 / 68    (Adware)
torrent3.0-win.exe  (6664d5916a41a93a40411b074dea1c6c)

9 / 68      (Adware)
sqliteencrypt.dll  (49cd32a6169dbb3d34e50b6c15cce74e)

20 / 68    (Adware)
setup.exe (by http://jjangq.co.kr)  (8d1c1d1e706ebafbbe4145af831e8cae)

4 / 68      (Adware)
220859.exe (BomulBox Searchbar by http://bomulbox.co.kr)  (425f2479fe956f67017c1910bc4a51a1)

4 / 68      (Adware)

 
Latest 30 of 37 files

The certificates below are also signed by TGSM Inc..

7D8725772359BB44707B7E208AE915C2  (Mar 17, 2013 to May 17, 2014)

7193DB486426289A17603DC315513E28  (Mar 05, 2012 to Apr 05, 2013)

655F3EAF0D3E7A560B415FFE5611AFDD  (Dec 14, 2009 to Feb 13, 2011)

3CF28BF78B7D2C503C83F61AB56BAFA8  (Jan 09, 2009 to Jan 09, 2010)

Remove TGSM Inc. Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to TGSM Inc. by Thawte, Inc. on February 11, 2011 with the serial number '5110a6616204b0264e74f3527fa2aa76'.