torangcommunications

Publisher Information

torangcommunications is a software publisher located in kangnam, Seoul in Korea*. The company is a primary distributor of unwanted software. Thre are 2 additional code signing certificates issued to this publisher.
Authority:
Thawte, Inc.

Valid from:
3/14/2012 9:00:00 AM

Valid to:
4/14/2013 8:59:59 AM

Subject:
CN=torangcommunications, O=torangcommunications, L=kangnam, S=seoul, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
4b8fea32f931a6055dd3a6fbd2efa432

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.torangcommunications, PUP.Installer.torangcommunications, PUP.torangcommunications.Installer (M), PUP.torangcommunications (M), PUP.torangco.Installer (M), PUP.torangco (M), PUP (M)
100.00%

Trend Micro House Call
ADW_KRADDARE, TROJ_GEN.F47V0101, TROJ_GEN.F47V1008
8.70%

AhnLab V3 Security
PUP/Win32.WindViewer, PUP/Win32.Addendum, PUP/Win32.Addenbar
6.52%

Malwarebytes
Adware.KorAd
4.35%

Trend Micro
ADW_KRADDARE
4.35%

McAfee
Artemis!21D8B69C9AD5, Artemis!84EB49F2DEAE
4.35%

Comodo Security
Heur.Suspicious, UnclassifiedMalware
4.35%

Avira AntiVirus
BDS/Backdoor.Gen3, TR/BHO.DC.830
4.35%

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h, AdWare.Delf
4.35%

NANO AntiVirus
Trojan.Win32.Shopper.cucvdl
2.17%

1 / 68      (Adware)
setup_kf020_m.exe  (10c67acf1afa24fa9cf49d7cc4d2b4a9)

1 / 68      (Adware)
utilbada.exe  (6a0033c0a7d80af2e8245db06b87a406)

1 / 68      (Adware)
setup_pid004_silent.exe  (41fe0be280da1401e299f441293bd038)

1 / 68      (Adware)
KEYWOR~2.DLL  (326bbd05796ac9a1c8dec6506313e7ff)

1 / 68      (Adware)
torangcomz.dll (torangcomz)  (7bde042843ebb28ae1756382e1416180)

1 / 68      (Adware)
ksagent.exe  (2027a02cd73d1b1c779aa59bbe7b23e7)

1 / 68      (Adware)
setup_kso1.exe  (af6b794e0e8600862f61347868aea663)

1 / 68      (Adware)
windviewer.exe  (4bc0e62dcd40c9d5c789cf00d8ddd8c7)

1 / 68      (Adware)
windopt.exe  (62b5e85c8b6bc178469944ba1644c825)

1 / 68      (Adware)
keywordfo.dll  (3d6606e4a04ab73b054ab6b9289ed01a)

1 / 68      (Adware)
197956  (53c87ae3fe7d8f0a5468c7f5dc91174e)

1 / 68      (Adware)
197850  (008614f6bdc48c37cd79c23bce605d6f)

1 / 68      (Adware)
keywordso.dll  (a25d637af5a4bcf6b56d10c6e928e3e2)

1 / 68      (Adware)
keywordfo.dll  (2411a8b47eedac40899dca048c4472b7)

1 / 68      (Adware)
windviewer.exe  (9b7e4e8a61c56ac1f204f90a99cf4b69)

1 / 68      (Adware)
keywordfo.dll  (2ae99c850c95e581c426b54cbddd3d88)

1 / 68      (Adware)
keywordfotmp_889  (4b64f53cb4e978ca2d539b857b7b7a73)

1 / 68      (Adware)
windvieweragent.exe  (fed32315e47dee331bed9f44529d50e3)

1 / 68      (Adware)
keywordso_uninstall.exe  (7d970953d335b06ed8ca8bd471e17bf9)

1 / 68      (Adware)
keywordso.dll  (f3b9ae719abe7e502ff9748cd66985ea)

1 / 68      (Adware)
keywordso.dll  (3f8be173a0b3bea90a2a8df17e8ba0d7)

1 / 68      (Adware)
windvo.dll  (c1df418e69c0b678864939daf7f84c17)

1 / 68      (Adware)
windviewer.dll  (8bb5176cc847ff40c9271b89508eb17a)

1 / 68      (Adware)
setup_kf011_m.exe  (2f8bb3fdce17093f45ff0fbe98814fe9)

1 / 68      (Adware)
keywordfo_uninstall.exe  (4750950622d5b32119fcd02ea5387eac)

1 / 68      (Adware)
keywordfo.dll  (14d40e559a24a6646598f9bde1b09583)

1 / 68      (Adware)
keywordfind.dll  (1dc7093d2ff175a6313eab3d8cf79d42)

1 / 68      (Adware)
keywordfo.dll  (b9949403174338186edf9316001e1bd9)

1 / 68      (Adware)
windvo_uninstall.exe  (4a6a1e3e5141a1917f0f90793100fadb)

1 / 68      (Adware)
windopt.exe  (c72eec8d7cac259c87b102a379cd0bbc)

 
Latest 30 of 46 files

The certificates below are also signed by torangcommunications.

09827727BDB71CF128B5AEB47CE2C8EA  (Apr 19, 2013 to May 20, 2014)

52ACAB754DEC6C8A2B35197339CD05F8  (Mar 08, 2010 to Mar 08, 2012)

The following publishers (by Authenticode signature organization name) are related.

* Note, the details and description above are based on the code signing digital signature issued to torangcommunications by Thawte, Inc. on March 14, 2012 with the serial number '4b8fea32f931a6055dd3a6fbd2efa432'.