ktd1191.exe

Update

SOVDWAER Gesellschaft fuer EDV-Loesungen mbH

The application ktd1191.exe, “Update Setup ” by SOVDWAER Gesellschaft fuer EDV-Loesungen mbH has been detected as a potentially unwanted program by 2 anti-malware scanners. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from sovdworld.de.
Publisher:

Product:
Update

Description:
Update Setup

MD5:
6f161e8b0b94260a5c0d8177c8fd3c1b

SHA-1:
53e67c4a8b99e4fdbfb70a62ece08e7e4bc94e14

SHA-256:
1344da2edbcaf9dcb9321891031b85165dc6f94e5ab649fbaa8724f423ddaca3

Scanner detections:
2 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/26/2024 6:43:04 PM UTC  (today)

Scan engine
Detection
Engine version

Clam AntiVirus
Win.Adware.Eorezo-374
0.98/21511

Reason Heuristics
PUP.InstallCore.CSH (L)
16.12.13.1

File size:
966.2 KB (989,408 bytes)

Copyright:
© SOVDWAER GmbH

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\ktd1191.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
12/5/2013 1:00:00 AM

Valid to:
12/10/2015 12:59:59 AM

Subject:
CN=SOVDWAER Gesellschaft fuer EDV-Loesungen mbH, OU=Entwicklung, O=SOVDWAER Gesellschaft fuer EDV-Loesungen mbH, L=Ludwigsburg, S=Baden-Wuerttemberg, C=DE

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
1D436C432A3C5AEC9C47198A5D345531

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:UQihpQhMzchcZUsimCxKIc6lJpchcZUsDMBTlP0QjcpMXVJok:U9YhwwcZ/56lJpwcZJGpff

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file ktd1191.exe has been seen being distributed by the following URL.

http://sovdworld.de/kunden/.../getfile.php?filename=ktd1191.exe

Remove ktd1191.exe - Powered by Reason Core Security