Akorea

Publisher Information

Akorea is a software publisher located in Haeundae-gu, Busan in Korea*. The company is a primary distributor of unwanted software. Thre are 4 additional code signing certificates issued to this publisher.
Remove Akorea Malware - Powered by Reason Core Security
Authority:
Thawte, Inc.

Valid from:
5/5/2012 9:00:00 AM

Valid to:
7/5/2013 8:59:59 AM

Subject:
CN=Akorea, O=Akorea, L=Haeundae-gu, S=BUSAN, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
2fae031ceaf57b56615a3998deb1d1fd

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
Unnamed.Threat.41, Unnamed.Threat.34, Unnamed.Threat.36, Unnamed.Threat.50, Unnamed.Threat.14, PUP.Akorea.a, PUP.Akorea.L, PUP.Akorea.Installer (M), PUP.Akorea (M)
89.66%

SUPERAntiSpyware
Trojan.Agent/Gen-FraudScan, Adware.Kraddare
62.07%

McAfee
FakeAlert-PZ, Artemis!5C5B9FEBDFE5, Artemis!63C34CD97BE4, Artemis!EC5B9E6213AE, Artemis!B4C5588ABA6B, Generic FakeAlert.hh
58.62%

avast!
Win32:Adware-AZQ [Adw], Win32:FakeAV-EKT [Trj], Win32:Adware-AUH [Adw]
58.62%

McAfee Web Gateway
Heuristic.BehavesLike.Win32.Suspicious-DTR.G, Artemis!5C5B9FEBDFE5, Artemis!EC5B9E6213AE, Artemis!B4C5588ABA6B, Artemis!1F8510081AEC
58.62%

ESET NOD32
Win32/Adware.IScan (variant), Win32/Adware.Kraddare.EB (variant), Win32/Adware.Kraddare (variant), Win32/Adware.Kraddare.CG (variant)
58.62%

MicroWorld eScan
Gen:Variant.Graftor.53956, Gen:Variant.Graftor.123892, Application.Generic.570318, Gen:Variant.Adware.Graftor.41005, Gen:Variant.Adware.Graftor.112065, Gen:Variant.Adware.Graftor.Elzob.43, Gen:Variant.Adware.Graftor.129002, Gen:Variant.Adware.Graftor.Elzob.4038
55.17%

Bitdefender
Gen:Variant.Graftor.53956, Gen:Variant.Graftor.123892, Application.Generic.570318, Gen:Variant.Adware.Graftor.41005, Gen:Variant.Adware.Graftor.112065
55.17%

Comodo Security
UnclassifiedMalware, ApplicUnwnt
55.17%

VIPRE Antivirus
Trojan.FakeAlert, Trojan.Win32.Generic, Trojan.Win32.Generic.pak!cobra
55.17%

1 / 68      (Adware)
uninst_vaccineup.exe (vaccineup by AKorea)  (9feaa807039e5ec0f80703e0379132cc)

1 / 68      (Adware)
EGutil.dll (vaccineup by AKorea)  (453efe3c50ec02fac29e151e5144b270)

1 / 68      (Adware)
livespeedsetup_gonggu.exe (livespeed installer by AKorea)  (2e574a895d50cb3095d9f7d7a829d0c6)

1 / 68      (Adware)
uninst_easyprotect.exe (easyprotect by AKorea)  (a95dbed5305180a7030176700dd09b91)

1 / 68      (Adware)
EGutil.dll (easyprotect by AKorea)  (9dab5370bd89ceac2b0d38bddb6bfc72)

1 / 68      (Adware)
livespeedsetup_good2.exe (livespeed installer by AKorea)  (154bf7c26244d5bf608d41e3f98460a4)

1 / 68      (Adware)
datawinuser.exe (by AKorea)  (41ed3182b93c833bb014ee7620958966)

1 / 68      (Adware)
speedlitesetup_ecube.exe (speedlite installer by AKorea)  (cf06bc3ae893b1b49f0d3264cc785a7f)

1 / 68      (Adware)
premiumpcse.exe (by AKorea)  (e7b395c46f678ec8deae859245894109)

1 / 68      (Adware)
carepcsetup_kan.exe (carepc Installer by UCF)  (7dc4799a908de8b3104027c87b5423f1)

11 / 68    (Adware)
uninst_vaccineclass.exe (vaccineclass by AKorea)  (67f3262ca5929c078cccdfad83fa6864)

24 / 68    (Adware)
EGutil.dll (vaccineclass by AKorea)  (957426d403aa90c5f4ac5cbc4e58c1c4)

29 / 68    (Adware)
speedcleanerse.exe (by AKorea)  (e549edaf224406db65fa9c75f2ec5f7c)

41 / 68    (Adware)

42 / 68    (Adware)
premiumpcsetup_pop.exe (premiumpc installer by AKorea)  (8a3c307e577d854c594971c02bcb67f8)

2 / 68      (Adware)
multiboansetup_pop.exe (multiboan installer by AKorea)  (6c83ab8ea05915759f63fcdcce960f93)

37 / 68    (Adware)
premiumpcsetup_off.exe (premiumpc installer by AKorea)  (eee7c9d1a53dfed481f58d1120759b40)

36 / 68    (Adware)
winuserdata.exe (by TMG)  (41ae341a6a7b57d6c5df9f6352cb6f90)

39 / 68    (Adware)
1f8510081aec2f1b4b053300c59e746c.exe (carepc by AKorea)  (1f8510081aec2f1b4b053300c59e746c)

29 / 68    (Adware)
speedlite.EXE (speedlite by AKorea)  (d9c01c45c48b345fb55cf117e766329d)

24 / 68    (Adware)
uninst_speedlite.exe (uninst_speedlite by AKorea)  (e27b2c56af55ad2f3afb892561c489b8)

33 / 68    (Adware)
userinfoconfig.exe (by AKorea)  (2c6fb2f8174e85fe832500e8b818f58d)

30 / 68    (Adware)
livespeedU.exe (livespeed by AKorea)  (b4c5588aba6b1e0ace5353fbc9033000)

12 / 68    (Adware)
livespeedse.exe (by AKorea)  (eda656c03ce0df0753824073b056eb8c)

34 / 68    (Adware)
speedliteU.exe (speedlite by AKorea)  (ec5b9e6213aef447e09e2d31f56d3bb2)

26 / 68    (Adware)
livespeed.EXE (livespeed by AKorea)  (63c34cd97be43f421b585252f1a792a8)

34 / 68    (Adware)
livespeedsetup_very.exe (livespeed installer by AKorea)  (3a1b048ca7b5c8de4965a25dc7c7df55)

18 / 68    (Adware)
speedlitese.exe (by AKorea)  (5c5b9febdfe5dbd626d015a6966cd096)

35 / 68    (Adware)
speedlitesetup_off.exe (speedlite installer by AKorea)  (0542fc557c2b454f08b24f1e114ede75)

The certificates below are also signed by Akorea.

47808D51BD832E4E938DE40E8ABCFACB  (Jun 28, 2013 to Jul 29, 2014)

5D613064725D2995334F25A0F88211D1  (May 19, 2011 to May 19, 2012)

1FD4E6E2D3011881D4A22C6056559DA3  (May 28, 2010 to May 29, 2011)

57AA8D37BE793A2E6812E737241714A8  (Apr 08, 2009 to Apr 09, 2010)

Remove Akorea Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to Akorea by Thawte, Inc. on May 05, 2012 with the serial number '2fae031ceaf57b56615a3998deb1d1fd'.