Clovermedia SL

Publisher Information

Clovermedia SL is a software publisher located in Tenerife, Spain*. The company is a primary distributor of unwanted software. Thre are 3 additional code signing certificates issued to this publisher.
Remove Clovermedia SL Malware - Powered by Reason Core Security
Authority:
GlobalSign nv-sa

Valid from:
2/12/2014 3:16:19 PM

Valid to:
2/13/2015 3:16:19 PM

Subject:
E=media@clovermediainter.com, CN=Clovermedia SL, O=Clovermedia SL, S=Tenerife, C=ES

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112168f91ef65a6728fffa559e8ed6a2eec5

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.ClovermediaSL.F, PUP.ClovermediaSL.L, PUP.Installer.ClovermediaSL.M, PUP.Installer.ClovermediaSL.P, PUP.ClovermediaSL.E, PUP.Tuguu, PUP.Installer.Tuguu, Threat.Tuguu.Bundler, PUP.Tuguu.Bundler, PUP.Tuguu.Clovermedia.Bundler (M)
100.00%

Dr.Web
Adware.Downware.2630, Adware.Downware.2532, Trojan.DownLoader9.33391, Trojan.DownLoader9.62498, Trojan.DownLoader11.4884
68.18%

Avira AntiVirus
APPL/DomaIQ.Gen, APPL/Bundler.DomaIQ.3, Adware/Strictor.55983, APPL/DomaIQ.A.10, PUA/DomaIQ.Gen
68.18%

McAfee Web Gateway
Heuristic.BehavesLike.Win32.Suspicious.H, Heuristic.LooksLike.Win32.Suspicious.I, PUP-FJV!A41C67C128AD, CryptDomaIQ, BehavesLike.Win32.CryptDoma.gh
68.18%

AVG
DomaIQ, DomaIQ_r.J, DomaIQ.R, Adware DomaIQ.CP, DomaIQ_r.K, Adware DomaIQ.CT, Adware DomaIQ.CI, Adware DomaIQ.CW, Adware DomaIQ.R
68.18%

MicroWorld eScan
Gen:Variant.Adware.Graftor.139070, Dropped:Adware.DomaIQ.AM, Application.Generic.602579, Gen:Variant.Application.Bundler.DomaIQ.3
68.18%

Agnitum Outpost
PUA.DomaIQ, PUA.Lollipop
68.18%

Bitdefender
Gen:Variant.Adware.Graftor.139070, Dropped:Adware.DomaIQ.AM, Application.Generic.602579, Gen:Variant.Application.Bundler.DomaIQ.3
68.18%

G Data
Gen:Variant.Adware.Graftor.139070, Dropped:Adware.DomaIQ.AM, Application.Generic.602579, Gen:Variant.Application.Bundler.DomaIQ
68.18%

Kaspersky
not-a-virus:AdWare.MSIL.DomaIQ, not-a-virus:AdWare.Win32.Lollipop, not-a-virus:HEUR:AdWare.MSIL.DomaIQ
65.91%

1 / 68      (Adware)
setup.exe  (046c62a65cdf8f58e7691d201cf8d33d)

1 / 68      (Adware)
setup.exe  (f299d6adac1b7fc0fb193821fc616361)

1 / 68      (Adware)
setup.exe  (72314609c25cdd2b32449037dbe702d7)

1 / 68      (Adware)
player setup.exe  (6c79540549cc50efacd0738520abbd3c)

1 / 68      (Adware)
player setup.exe  (b09b49d993d5972a384890c1f97b957a)

1 / 68      (Adware)
00000000  (c98408a8a179bc989126b7d055cd09c5)

1 / 68      (Adware)
player setup.exe  (f3371c315e94900a600bb02861d15060)

1 / 68      (Adware)
playersetup.exe  (d625ea3f66e4fda9be7db24f6fd0eaa7)

1 / 68      (Adware)
playersetup.exe  (0e4904d14e6fffa84786f14b0235942f)

1 / 68      (Adware)
00000000  (541f09374818c68b6d2c10d2a6cb6b5c)

35 / 68    (Adware)
virusshare_61f3633fe8151700d6f6d81a681a5f30  (61f3633fe8151700d6f6d81a681a5f30)

1 / 68      (Adware)
setup.exe  (f55890db54b1a9dd684cf2d1c31d9a1b)

1 / 68      (Adware)
player setup.exe  (d052d167c26a4754f717e6ab408be09b)

1 / 68      (Adware)
player setup.exe  (daff1f7f009cc090dc3f45d39ba79a49)

39 / 68    (Adware)
player setup.exe  (9ed5256276e2744b08e8ae55df7a07b0)

37 / 68    (Adware)
player setup.exe  (48a32e28c48903c127fa760e6fe0ac1f)

40 / 68    (Adware)
flashplayer.exe  (f171cc9daa501fef0dde1c292432916a)

36 / 68    (Adware)
00000000  (7babb1c0f2bb2f192e85d90b6d61ba34)

37 / 68    (Adware)
setup.exe  (5a05a0192483c09aecdbdf58c30ef6fe)

39 / 68    (Adware)
00000002  (6885b07a4a3b50a79bf28f3f66eb5267)

36 / 68    (Adware)
setup.exe  (854f40141aba70f5205578e354fccfd3)

36 / 68    (Adware)
setup.exe  (6f4db56b9867bd3fc51b62281cf5f1d9)

37 / 68    (Adware)
player setup.exe  (e3f7c7c92d29100898d78e96409cf6c2)

37 / 68    (Adware)
setup.exe  (e844fbf050c3a708062fe461576f51b2)

35 / 68    (Adware)
player setup.exe  (5281e309313bf9b33142d99fa424936e)

34 / 68    (Adware)
player setup.exe  (4c6646c06ffa7c5ca031f1db4b556c51)

32 / 68    (Adware)
java.exe  (34d5f89cfa96fe1003f58fbb73ca887e)

35 / 68    (Adware)
setup.exe  (036ba2bd4dc08836e76fda32ba3f2ce5)

29 / 68    (Adware)
player setup.exe  (2d8510c016d1c028e678abd6ed97e867)

28 / 68    (Adware)
player setup.exe  (4f2be300ffedbf85f0d939167eab8066)

 
Latest 30 of 44 files

Downloads URLs for files signed by Clovermedia SL.

1 / 68      (Adware)

1 / 68      (Adware)
http://www.winrar.com/.../Setup.exe  (72314609c25cdd2b32449037dbe702d7)

36 / 68    (Adware)
http://www.winrar.com/.../Setup.exe  (6f4db56b9867bd3fc51b62281cf5f1d9)

32 / 68    (Adware)
http://www.javaabc123.info/.../Java.exe  (34d5f89cfa96fe1003f58fbb73ca887e)

28 / 68    (Adware)

28 / 68    (Adware)
http://download.aboede.com/.../flashplayer.exe  (1b171a597004e70276b7fd63e2e9899a)

The following websites host and distribute files published by Clovermedia SL.

The certificates below are also signed by Clovermedia SL.

1121FAB97DC7FB0477755E47A50ECFDC36A0  (Apr 29, 2014 to Apr 30, 2015)

63DA06E73C9409AFD0724B0C61E7B745  (Mar 11, 2014 to Mar 12, 2015)

281161B1143F2B  (Feb 13, 2014 to Feb 13, 2015)

The following publishers (by Authenticode signature organization name) are related.

Remove Clovermedia SL Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to Clovermedia SL by GlobalSign nv-sa on February 12, 2014 with the serial number '112168f91ef65a6728fffa559e8ed6a2eec5'.