Korea Contents Network

Publisher Information

Korea Contents Network is a software publisher located in "Seocho gu ", Seoul in Korea*. The company is a primary distributor of unwanted software. There is one additional code signing certificate issued to this publisher.
Remove Korea Contents Network Malware - Powered by Reason Core Security
Authority:
Thawte, Inc.

Valid from:
3/7/2012 9:00:00 AM

Valid to:
3/8/2013 8:59:59 AM

Subject:
CN=Korea Contents Network, O=Korea Contents Network, L="Seocho gu ", S=Seoul, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
3c3fb7f3f4b4598823ce40d67cca7266

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.KoreaContentsNetwork.J, PUP.KoreaContentsNetwork.P, PUP.KoreaContentsNetwork.E, PUP.KoreaContentsNetwork.Installer (M), PUP.KoreaContentsNetwork (M)
100.00%

Vba32 AntiVirus
AdWare.CloverPlus, AdWare.Agent.yje
77.78%

IKARUS anti.virus
not-a-virus:AdWare.Win32.CloverPlus, not-a-virus:AdWare.Win32.Agent, PUA.CloverPlus, Win32.SuspectCrc
77.78%

Comodo Security
ApplicUnwnt, UnclassifiedMalware, Heur.Suspicious, Application.Win32.CloverPlus.AE
72.22%

ESET NOD32
Win32/Adware.CloverPlus.AB (variant), Win32/Adware.HKVEECC (variant), Win32/Adware.CloverPlus.AE (variant), Win32/Adware.IAWUALR (variant)
66.67%

AhnLab V3 Security
PUP/Win32.AdMatching, Win-PUP/Helper.AdMatching.628880.B
66.67%

Malwarebytes
Adware.KorAd, Adware.K.AdMatching, Adware.K.ShoppingAd, Adware.CloverPlus.K
61.11%

NANO AntiVirus
Trojan.Win32.CloverPlus.baybws, Trojan.Win32.CloverPlus.bblhol, Trojan.Win32.Siggen.ccdghx, Trojan.Win32.CloverPlus.bseoko
61.11%

VIPRE Antivirus
Trojan.Win32.Generic, Trojan.Win32.Generic.pak!cobra, Adware.Agent
61.11%

Avira AntiVirus
Adware/Rogue.628880, Adware/CloverPlus.AB, Adware/ClovPlus.636, Adware/CloverPlus.hg.3, Adware/Rogue.628912, Adware/Rogue.120976
61.11%

1 / 68      (Adware)
updater112.exe  (776c6f203bcbecbd7d52ad060ed87bcc)

1 / 68      (Adware)
admatching.exe  (df2bdead526ed266d93226260f6fee3a)

1 / 68      (Adware)
adinstall_ad003.exe  (80619eb723e5a6c235bff1656b5f7d28)

1 / 68      (Adware)
~tmp_file_006.exe  (6962bfdf71cdcf4f855330487ea34367)

11 / 68    (Adware)
ad_3.exe  (6552cba8baadd050b71df2f3dc0f8147)

15 / 68    (Adware)
adinstall_ad015.exe  (2be6a5488d41cb0a5b9dba01dca9a207)

30 / 68    (Adware)
admsys.exe  (96d11862d8bcdda7bdf8a0b4c2aed4f2)

28 / 68    (Adware)
admatching.exe  (58a9a90626bc2c2df5396f6f0bc17b86)

22 / 68    (Adware)
adinstall_ad019.exe  (675b6e9745f7bb13e6900abe134525a5)

16 / 68    (Adware)
adinstall_ad009.exe  (53e76a60fed7f3a8533cf618d6864708)

26 / 68    (Adware)
adinstall_ad019.exe  (b17496e5818c4d267f30ae18a3148a03)

26 / 68    (Adware)
adinstall_ad025.exe  (4b2c463fb4c58a3716ad7e1f9ad018a4)

15 / 68    (Adware)
adinstall_ad003.exe  (ff25df64bec2bd112e37e07fc4e23447)

20 / 68    (Adware)
adinstall_ad026.exe  (886984b7c39c5b15e96f4e958b37c249)

32 / 68    (Adware)
애드매칭.exe  (713d1b75328bc367185abcf2a631b4da)

31 / 68    (Adware)
adinstall_ad026.exe  (f0ed6b4554ce48073dadf4e2748b253e)

27 / 68    (Adware)
adinstall_ad009.exe  (b270cd6f652c87080ba2d67cbe0f0c66)

13 / 68    (Adware)
adinstall.exe (by Korea Contents Network)  (335300a5a4c1cceb5973b15fe97c3067)

The following certificate is also signed by Korea Contents Network.

21EE4A0E6A9CF5DFE2A088CE59AC500C  (Jan 14, 2013 to Apr 16, 2014)

Remove Korea Contents Network Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to Korea Contents Network by Thawte, Inc. on March 07, 2012 with the serial number '3c3fb7f3f4b4598823ce40d67cca7266'.