TGSM Inc.

Publisher Information

TGSM Inc. is a software developer located in Haeundae-gu, Busan in Korea*. The company is a primary distributor of unwanted software. Thre are 4 additional code signing certificates issued to this publisher.
Remove TGSM Inc. Malware - Powered by Reason Core Security
Authority:
Thawte, Inc.

Valid from:
3/5/2012 9:00:00 AM

Valid to:
4/5/2013 8:59:59 AM

Subject:
CN=TGSM Inc., OU=EC Team, O=TGSM Inc., L=Haeundae-gu, S=Busan, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
7193db486426289a17603dc315513e28

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.TGSM.I, PUP.TGSM.M, PUP.TGSM.J, PUP.TGSM.G, PUP.Installer.TGSM.F, PUP.OpenShopper.TGSM (M), PUP.OpenShopper.TGSM.Installer (M)
100.00%

AVG
OpenShopper.D, Skodna.Generic_r.I, OpenShopper.A
62.50%

Clam AntiVirus
Adware.Openshopper-2, Adware.Openshopper-3, Adware.Openshopper-1
47.50%

Trend Micro House Call
TROJ_GEN.RCBH1B8, TROJ_SPNR.14BD13, ADW_OPENSHOPPER, ADW_OPENSHOPER, TROJ_GEN.RCBH1L9, TROJ_GEN.F47V1207, TROJ_GEN.RCBH1AU, TROJ_GEN.F47V0715, TROJ_GEN.RCBH1HM
45.00%

ESET NOD32
Win32/Adware.OpenShopper (variant)
45.00%

Avira AntiVirus
ADWARE/Adware.Gen, Adware/OpenShopper.A.36, Adware/OpenShopper.D.5, Adware/Openshoppe.H, Adware/OpenShopper.D.31, Adware/OpenShop.ajy
42.50%

Kingsoft AntiVirus
Win32.Troj.Generic.a.(kcloud), VIRUS_UNKNOWN
37.50%

Comodo Security
ApplicUnwnt, UnclassifiedMalware, Heur.Suspicious, ApplicUnwnt.Win32.AdWare.OpenShopper.~SHO
32.50%

AhnLab V3 Security
PUP/Win32.SmartTip, PUP/Win32.OpenKeyword, PUP/Win32.SmartWeb, PUP/Win32.Tor
32.50%

Malwarebytes
Adware.KorAd, Adware.K.OpenShopper, Adware.OpenShopper.K, Adware.ShareBox
30.00%

1 / 68      (Adware)
SmartTipS.exe (SmartTipS by TGSM)  (bd4be2ff37d8ee9869061fdf81fa8c63)

1 / 68      (Adware)
SmartTipD.exe (SmartTipD by TGSM)  (18700562680e92770a4ccea4f29f7dee)

1 / 68      (Adware)
SmartTipC.exe (SmartTipC by TGSM)  (91a5ac22c5f7946644f5a7d099d98960)

1 / 68      (Adware)
OpenKeywordD.exe (OpenKeywordD by TGSM)  (11f95a87124b193c8634bafd661ae4c7)

1 / 68      (Adware)
setup.exe (by http://downs.co.kr)  (e1cb2a4ca709d06f6b133fea103af1a4)

1 / 68      (Adware)
setup.exe (by http://sharebox.co.kr)  (fad21214e6b8fb31a8e4a81efc55609c)

1 / 68      (Adware)
BomulBoxCtrl.dll (BOMULBOX by TGSM)  (6aeeced86978794624a073e30babb11f)

1 / 68      (Adware)
JJangQCtrl.dll (JJangQCtrl by TGSM)  (78c0ce06cd14750fa4a29c915a0862ca)

1 / 68      (Adware)
DownsCtrl.dll (by TGSM)  (7f61f58008ce82e55afd3b0f87f99232)

1 / 68      (Adware)
ShareBoxCtrl.dll (ShareBoxCtrl by TGSM)  (228bd35fefbb55e03c559314f8c264f6)

1 / 68      (Adware)
41156.exe (by http://openkeyword.co.kr)  (5926b09d0fd0b8e9445603ab30196939)

1 / 68      (Adware)
~tmp_file_002.exe (by http://smarttip.co.kr)  (da271a3696c22051ed93bd793d74ee18)

1 / 68      (Adware)
1199260759.exe  (beae7a703b5578c76eec4aff2a2f7522)

1 / 68      (Adware)
1199250494.exe (by http://smarttip.co.kr)  (0583a1acbac72927751191276985809d)

14 / 68    (Adware)
torrent3.1_win.exe  (ae97545af7e0d0554fbbaa3704e2c4fd)

9 / 68      (Adware)
SmartWS.exe (SmartWS by TGSM)  (1cea1fada49b7a9c74d5ba56196a6413)

9 / 68      (Adware)
SmartWD.exe (SmartWD by TGSM)  (b85597fde1a1abbf2185399068d8a3bf)

16 / 68    (Adware)
setup.exe (by http://sharebox.co.kr)  (fd7145d5b8a6cb7603c7d64cc733b9bb)

14 / 68    (Adware)
stextern.exe (by http://smarttip.co.kr)  (50b23e7349a479ff18b3d49fe041770f)

16 / 68    (Adware)
okextern.exe (by http://openkeyword.co.kr)  (e723d5fa35faf57d03e0e23e292aa79c)

6 / 68      (Adware)
ShareBoxUp.exe (by TGSM)  (5fc86f9d428a3dcafdc1820f74499267)

4 / 68      (Adware)
shareboxdown2.exe (by TGSM)  (3ea07951d6b98b8a40abfee862f72b57)

4 / 68      (Adware)
ShareBoxDown.exe (by TGSM)  (fe780e10a4e100e77dfecd5fb50af1e4)

20 / 68    (Adware)
setup.exe (by http://sharebox.co.kr)  (5a924b5cf5b043a21e60d3a126d96a3f)

7 / 68      (Adware)
ShareBoxC.exe (SHAREBOX by TGSM)  (d1b7b894ea3de7c49b3bb665853a401d)

18 / 68    (Adware)
swextern.exe (SmartWeb Control by http://smartw.co.kr)  (9e9c259b6ce05665edfa790e4e7dd0aa)

18 / 68    (Adware)
6548687.exe (SmartWeb Control)  (213163efa22f0318b538f71863494dca)

16 / 68    (Adware)
6533281.exe (SmartWeb Control by http://smartw.co.kr)  (77ba75d3c58ce51e7914fa2832ac8456)

10 / 68    (Adware)
OpenKeywordD.exe (OpenKeywordD by TGSM)  (8ee3cdaa2ea60856425525bf738b07b9)

9 / 68      (Adware)
ButtonGuideD.exe (ButtonGuideD by TGSM)  (e3de5c102fbc25db9403ee3b742ed184)

 
Latest 30 of 40 files

Downloads URLs for files signed by TGSM Inc..

14 / 68    (Adware)
http://util.hibogo.net/Torrent3.1_win.exe  (ae97545af7e0d0554fbbaa3704e2c4fd)

The following websites host and distribute files published by TGSM Inc..

The certificates below are also signed by TGSM Inc..

7D8725772359BB44707B7E208AE915C2  (Mar 17, 2013 to May 17, 2014)

5110A6616204B0264E74F3527FA2AA76  (Feb 10, 2011 to Mar 12, 2012)

655F3EAF0D3E7A560B415FFE5611AFDD  (Dec 14, 2009 to Feb 13, 2011)

3CF28BF78B7D2C503C83F61AB56BAFA8  (Jan 09, 2009 to Jan 09, 2010)

Remove TGSM Inc. Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to TGSM Inc. by Thawte, Inc. on March 05, 2012 with the serial number '7193db486426289a17603dc315513e28'.