utilkoreafd_setup.exe

utilkoreafd_setup

NKsolution Corp.

The application utilkoreafd_setup.exe by NKsolution has been detected as a potentially unwanted program by 15 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software.
Publisher:
NK Solution  (signed by NKsolution Corp.)

Product:
utilkoreafd_setup

Version:
1, 0, 0, 1

MD5:
b134c88dd76e5dbee8ae7cc930b74103

SHA-1:
fb2e953af6bf125fb704647e7d1ceb17f4d13256

Scanner detections:
15 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 12:54:13 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Fraud.Gen4
7.11.68.20

avast!
Win32:PUP-gen [PUP]
2014.9-151202

Comodo Security
UnclassifiedMalware
15749

ESET NOD32
Win32/Adware.Kraddare.GZ (variant)
9.8176

Fortinet FortiGate
W32/FakeAV.OX!tr
12/2/2015

F-Prot
W32/FakeAlert.UA.gen
v6.4.7.1.166

IKARUS anti.virus
Win32.SuspectCrc
t3scan.2.0.0.0

K7 AntiVirus
Riskware
13.164.8447

Kaspersky
HEUR:Trojan-FakeAV.Win32.Onescan
14.0.0.1033

McAfee
Generic FakeAlert.is
5600.6564

Panda Antivirus
Suspicious file
15.12.02.08

Sophos
Mal/FakeAV-OX
4.87

SUPERAntiSpyware
Trojan.Agent/Gen-FraudScan[Prod]
9472

Trend Micro House Call
TROJ_GEN.F47V0329
7.2.336

VIPRE Antivirus
Trojan.FakeAlert
16398

File size:
221.4 KB (226,664 bytes)

Product version:
1, 0, 0, 1

Copyright:
Copyright (C) NK Solution All rights reserved.

Original file name:
utilkoreafd_setup.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Windows\System32\utilkoreafd_setup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/7/2010 9:00:00 AM

Valid to:
5/8/2011 8:59:59 AM

Subject:
CN=NKsolution Corp., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=NKsolution Corp., L=Jaesong-dong Haeundae-gu, S=Haeundae-gu, C=KR

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5DFBADE2203D406F2D7510DFBAADC483

File PE Metadata
Compilation timestamp:
3/23/2011 2:11:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:BLlSKvyXi1IENpkRDxl/30GgPLvIjuothhJH65bRDu:BLceyS1qRDxl/TuTpothh2Zu

Entry address:
0x179350

Entry point:
60, BE, 00, 50, 54, 00, 8D, BE, 00, C0, EB, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89...
 
[+]

Entropy:
7.8681

Packer / compiler:
UPX 2.90LZMA

Code size:
212 KB (217,088 bytes)

Remove utilkoreafd_setup.exe - Powered by Reason Core Security