C-NetMedia

Publisher Information

C-NetMedia is a software publisher located in Mobile, Alabama in the United States*. The company is a primary distributor of unwanted software. There is one additional code signing certificate issued to this publisher.
Remove C-NetMedia Malware - Powered by Reason Core Security
Authority:
VeriSign, Inc.

Valid from:
11/14/2006 1:00:00 AM

Valid to:
11/16/2007 12:59:59 AM

Subject:
CN=C-NetMedia, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=C-NetMedia, L=Mobile, S=Alabama, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
38f51432abad3aa35011f824e0c565ec

Scanner detections:
Detections  (96% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.CNetMedia.L, PUP.CNetMedia.I, PUP.CNetMedia.K, PUP.CNetMedia.D, Common.PUP.CNetMedia.E, PUP.Installer.CNetMedia.F, PUP.Installer.CNetMedia.H, PUP.CNetMedia.Installer (M), PUP.CNetMedia (M)
100.00%

Fortinet FortiGate
Misc/AntiSpyware, Riskware/AntiSpyware
38.46%

Vba32 AntiVirus
Signed-FraudTool.Win32.SpywareBot.i
30.77%

VIPRE Antivirus
C-NetMedia, Threat.394387
26.92%

IKARUS anti.virus
Trojan-FakeAV.C-NetMedia, Trojan.SuspectCRC
19.23%

Prevx
Heuristic: Suspicious Browser Help Object, Heuristic: Suspicious File With Bad Child Associations, Heuristic: Suspicious File With Bad Parent Associations, High Risk Worm
15.38%

ESET NOD32
Win32/AdWare.SpywareRemover.F application, multiple threats, Detection.Undefined
11.54%

Kingsoft AntiVirus
VIRUS_UNKNOWN
11.54%

Avira AntiVirus
TR/Fraud.Gen, SPR/Fake.RegSwep
11.54%

Trend Micro House Call
Mal_FakeAV-20, Suspicious_GEN.F47V0912, TROJ_GEN.RCBH1JP
11.54%

1 / 68      (Adware)
Launcher.exe (Launcher by RegistrySmart)  (412a943768c74c06db9955d8cba40ed4)

1 / 68      (Adware)
ddll.exe (by RegistrySmart)  (0002dddba512e20c3f82aaab8bad8b4d)

1 / 68      (Adware)
tcl.dll (Tcl 8.4 for Windows by ActiveState)  (792ae3bdd7e03defff10b36e0684ea80)

1 / 68      (Adware)
Launcher.exe (Launcher by RegistrySmart)  (ef4a769a8eeeccb9b9bd2616c24cf792)

1 / 68      (Adware)
RegistrySmart.EXE (RegistrySmart Application)  (b13f9d8e3d5c88f0ddad896d7fe33a88)

1 / 68      (Adware)
spybot setup.exe (by C-NetMedia)  (9aa90f7b548c51b1f310e2e83b72ae61)

1 / 68      (Adware)
setup.exe (by RegistrySmart)  (1a4bc6cd2925e167a23b31c32d9b5d8c)

5 / 68      (Adware)
Launcher.exe (Launcher by RegistrySmart)  (5477fc01017e9bd3565414a5dd33f50f)

7 / 68      (Adware)
RegistrySmart.EXE (RegistrySmart Application)  (8fa8acb2fb216ff1a838f278e2536556)

1 / 68      (Adware)
spywarebot.lnk (7-Zip by Igor Pavlov)  (e2320e4fdeccb140195b1882549ff2d1)

2 / 68      (Adware)
RegistrySmart.EXE (RegistrySmart Application)  (5daa3c71d519bbccd1ab0d9b238ffd18)

2 / 68      (Adware)
Launcher.exe (Launcher by RegistrySmart)  (b60cec180ddb4069871051d8f2a22ca9)

6 / 68      (Adware)
vistasetup.exe (by C-NetMedia)  (b27a5986ecaa764331a6e0c91f6c737d)

7 / 68      (Adware)
setup.exe (by RegistrySmart)  (ecc004d453c55f5c373c019653d05c4a)

7 / 68      (Adware)
antispyfilter.amd64.sys  (2148b94cf529ce5fd3445b3c111d0f09)

2 / 68      (Adware)
Launcher.exe (Launcher by AdwareAlert)  (04fc6829cb0a9242fb6ce70d9ed6669d)

2 / 68      (Adware)
AdwareAlert.exe (AdwareAlert by C-NetMedia)  (e460b62672ce7e1b29283b78b9faf8a0)

27 / 68    (Adware)
setupxv.exe (7-Zip by Igor Pavlov)  (7f87595b4fcc7df7b0011f6ec5bbfb84)

9 / 68      (Adware)
wrar362.exe (by SpywareBot)  (25557a370003f45d22a365f04167a8a9)

4 / 68      (Adware)
setup.exe (by SpywareBot)  (283a9c1922c2125a77b5593eb5129d61)

5 / 68      (Adware)
setup.exe (by RegistrySmart)  (7821988f500d80a7d3fbef020410b5fa)

1 / 68      (inconclusive)
zlib.dll (zlib)  (860617d08b2bc7ea4f65ae408ea2ce52)

1 / 68      (Adware)
tcl.dll (Tcl 8.4 for Windows by ActiveState)  (ac8788d8aa30e81db16a8bd99f69d175)

1 / 68      (Adware)
regcleaner.dll (RegClean)  (793fc1b03238aecea9df66c1246e1774)

2 / 68      (Adware)
Launcher.exe (RegistryBot by C-NetMedia)  (88aae9828cc2a278e34d50cc83f6812a)

3 / 68      (Adware)
RegistryBot.EXE (RegistryBot by C-NetMedia)  (1172cd27e81f5f6c21c33ad83f93347c)

The following certificate is also signed by C-NetMedia.

02A78994E8042BC50C7A333E91F74B3D  (Sep 19, 2007 to Nov 14, 2010)

Remove C-NetMedia Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to C-NetMedia by VeriSign, Inc. on November 14, 2006 with the serial number '38f51432abad3aa35011f824e0c565ec'.