Korea Contents Network

Publisher Information

Korea Contents Network is a software publisher located in Seocho-gu, Seoul in Korea*. The company is a primary distributor of unwanted software. There is one additional code signing certificate issued to this publisher.
Remove Korea Contents Network Malware - Powered by Reason Core Security
Authority:
Thawte, Inc.

Valid from:
1/14/2013 9:00:00 AM

Valid to:
4/16/2014 8:59:59 AM

Subject:
CN=Korea Contents Network, OU=IT Team, O=Korea Contents Network, L=Seocho-gu, S=SEOUL, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
21ee4a0e6a9cf5dfe2a088ce59ac500c

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.KoreaContentsNetwork.K, PUP.KoreaContentsNetwork.P, PUP.KoreaContentsNetwork.Q, PUP.KoreaContentsNetwork.K, PUP.KoreaContentsNetwork.O, PUP.KoreaContentsNetwork.Installer (M), PUP.KoreaContentsNetwork (M)
100.00%

Comodo Security
Application.Win32.CloverPlus.AE, ApplicUnwnt, Application.Win32.Adware.CloverPlus.A, UnclassifiedMalware
74.00%

McAfee
Artemis!7593670FDA31, Artemis!489D675B6104, Artemis!83F1ABB866A2, Artemis!59AF78C79249, Artemis!EF0F72893838, Artemis!4EA8F28E7316, PWS-Zbot.dx
72.00%

ESET NOD32
Win32/Adware.CloverPlus.AB (variant), Win32/AdWare.CloverPlus.AF (variant), Win32/Adware.CloverPlus.AE (variant), Win32/AdWare.Kraddare.JP (variant)
68.00%

AVG
Generic5, Win32/DH, Generic6
68.00%

VIPRE Antivirus
Trojan.Win32.Generic, Trojan.Win32.Generic.pak!cobra, Trojan.Win32.Generic!SB.0, CloverPlus, Adware.Maltrec
66.00%

Avira AntiVirus
TR/Rogue.1558128, Adware/CloverPlus.AB.5, Adware/CloverPlus.C, TR/Symmi.31567.19, TR/Symmi.31567.24, TR/Symmi.31567.23, TR/Symmi.31567.27
66.00%

McAfee Web Gateway
Artemis!7593670FDA31, Artemis!489D675B6104, Artemis!83F1ABB866A2, Artemis!59AF78C79249, Heuristic.BehavesLike.Win32.Suspicious-BAY.G
64.00%

IKARUS anti.virus
Trojan.SuspectCRC, Win32.SuspectCrc, AdWare.Win32.Kwsearchguide, PUA.CloverPlus, AdWare.ClovPlus
64.00%

Malwarebytes
Adware.CloverPlus, Adware.K.AdMatching, Adware.KorAd, Adware.CloverPlus.K, Adware.Korad
62.00%

1 / 68      (Adware)
adinstall_ad043.exe  (2cac706ea0ec1577c831c0d089b22b49)

1 / 68      (Adware)
metablognewissues.exe  (f7768bc9b4cfe7c0d033ba5249173947)

1 / 68      (Adware)
adinstall.exe (by Korea Contents Network)  (e8e91cde65a37018dcd3c19347fb7835)

1 / 68      (Adware)
adinstall_ad035.exe  (62159e236ec18bdb6b3d0fe6508031da)

1 / 68      (Adware)
adinstall_ad040.exe  (06916aa2ea6263c85a21ba24f89124da)

1 / 68      (Adware)
admatching.dll  (60cd95995a3f2a82180f5727da3c83a7)

1 / 68      (Adware)
adinstall_ssi006.exe  (b2b642e2e2f30867fc121bb32c82e6c6)

1 / 68      (Adware)
adinstall_ad054.exe  (31ceff607209aa57d3767cd63bbce399)

38 / 68    (Adware)
ssiinstall.exe (SSI by Korea Contents Network,Inc)  (0db86e15df157493bfe8ae3c09305571)

1 / 68      (Adware)
adinstall_ssi009.exe  (5c3a46a98260ec69771e13092cf08c56)

1 / 68      (Adware)
adinstall_ad052.exe  (1207ef1fe5c5d78566eecce80750d36f)

38 / 68    (Adware)
ssiinstall.exe (SSI by Korea Contents Network,Inc)  (b0d7a0cc98f91c9a3333a2e26e2b1d8a)

1 / 68      (Adware)
adinstall_ssi005.exe  (3b3d88afb6a4f5d8d44c0e3b950e5a5a)

38 / 68    (Adware)
ssiinstall.exe (SSI by Korea Contents Network,Inc)  (d3f8288253f61d9debdbbf46a81eef33)

38 / 68    (Adware)
adinstall_ssi008.exe  (65a2e5e34e4d4308eb60b0f81cd51600)

37 / 68    (Adware)
adinstall_ssi018.exe  (74a64f0f431067cea9cd0b84dabcdba2)

18 / 68    (Adware)
adinstall.exe (by Korea Contents Network)  (33d11073d2d938140fb7b55c4f34ca6f)

33 / 68    (Adware)
setup_files1.exe  (20c8a8318bea060b220f5b1065c853af)

25 / 68    (Adware)
adinstall_ad033.exe  (5fb9854b5fd99a683ee2f7b227460fc2)

25 / 68    (Adware)
adinstall_ad031.exe  (f489c013c2bbd51cda040dbb039a4bf7)

25 / 68    (Adware)
adinstall_ad046.exe  (b087083414c54799240d8400278d81e2)

12 / 68    (Adware)
adinstall_sc001.exe  (64e7bdcb90ce4ece584af80b398eaa2b)

39 / 68    (Adware)
tmp1b5c.tmp.exe  (2d3dd660d5630a18bb3b38999289a907)

22 / 68    (Adware)
admsys.exe  (bd899879dd354d1a083ad4befaa88d48)

25 / 68    (Adware)
wiseman.EXE  (03760b878ce879df4d1666fc839b016e)

30 / 68    (Adware)
wmsinstall.exe (Wiseman by Korea Contents Network,Inc)  (eab671b7dfd3af282078069ec8c9a295)

25 / 68    (Adware)
tmp2da4.tmp.exe  (3cdb98c749ff9364a4f7f6ced27447b4)

31 / 68    (Adware)
SSIagent.EXE  (75bc16870ee222dfc10bb63aa06a8bba)

25 / 68    (Adware)
SSI.EXE  (37ee98e6d32abc38784c3390b2159b8d)

2 / 68      (Adware)
ssi.dll  (700e2c3ced6f2791fd3deb1b10fd1a46)

 
Latest 30 of 90 files

Downloads URLs for files signed by Korea Contents Network.

25 / 68    (Adware)
http://api.wisemansupport.com/.../adInstall_wms100.exe  (3cdb98c749ff9364a4f7f6ced27447b4)

The following certificate is also signed by Korea Contents Network.

3C3FB7F3F4B4598823CE40D67CCA7266  (Mar 07, 2012 to Mar 08, 2013)

Remove Korea Contents Network Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to Korea Contents Network by Thawte, Inc. on January 14, 2013 with the serial number '21ee4a0e6a9cf5dfe2a088ce59ac500c'.