CoolMirage Ltd.

Publisher Information

CoolMirage Ltd. is a software developer located in Tel Aviv, Israel*. The company is a primary distributor of unwanted software. Thre are 2 additional code signing certificates issued to this publisher.
Remove CoolMirage Ltd. Malware - Powered by Reason Core Security
Authority:
Thawte, Inc.

Valid from:
6/6/2013 2:00:00 AM

Valid to:
6/7/2014 1:59:59 AM

Subject:
CN=CoolMirage Ltd., O=CoolMirage Ltd., L=Tel Aviv, S=Israel, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
110f603e63c86349a5f243ea06966f33

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.CoolMirage.Installer (M), Adware.Crossrider.CoolMirage (M), PUP.CoolMirage (M), PUP.CoolMirage.installdaddy (M)
100.00%

McAfee
RDN/Generic PUP.x!chv, Artemis!CA229EF63586, RDN/Generic PUP.x!cgx, Artemis!9051C5655F5F, Artemis!7A125758251F, RDN/Generic PUP.x!c2q
22.00%

VIPRE Antivirus
Crossrider, Threat.4789396
22.00%

Trend Micro House Call
TROJ_GEN.R08NH07G614, TROJ_GEN.R08NC0EKT14, TROJ_GEN.R047B01FH14, TROJ_GEN.R0C1H07FN14, TROJ_GEN.R00JH07FO14, TROJ_GEN.R0C1C0EHS14
22.00%

Kaspersky
not-a-virus:AdWare.Win32.AdLoad
22.00%

McAfee Web Gateway
Artemis!PUP , RDN/Generic PUP.x!cgp, Artemis!E725706AC63A, Artemis!9051C5655F5F, Artemis!7A125758251F, BehavesLike.Win32.Dropper.hh
22.00%

Antiy Labs AVL
GrayWare[AdWare:not-a-virus]/Win32.AdLoad, Trojan/Win32.TSGeneric
22.00%

Baidu Antivirus
Adware.Win64.Crossrider, Adware.Win32.CrossAd, Adware.Win32.AdLoad, Adware.Win32.CrossRider, PUA.Win32.CrossRider, Adware.Win64.CrossAd
22.00%

Panda Antivirus
Trj/CI.A, PUP/MultiToolbar.A, Trj/Chgt.A
22.00%

Jiangmin
Adware/Adload.awk, Adware/Adload.bfr, Adware/Adload.ayf, Adware/Adload.awo, AdWare/Lyckriks.ff, Adware/Adload.avz, Adware/Adload.bkg
22.00%

1 / 68      (Adware)
fdu_130106_757.exe  (b423ad47934e70742c2d95a38736ea94)

1 / 68      (Adware)
bqtpzbgd.exe  (f8b3358310b782d818a7724896561474)

1 / 68      (Adware)
bpq8bax5.exe  (ecf2bdef8da79c3078d76d853ccb1031)

1 / 68      (Adware)
hdvid-codec v9.0-buttonutil64.dll  (20177008a329c1d1cfc57fd56f38cbe8)

36 / 68    (Adware)

1 / 68      (Adware)
www_torntv-tvv_org  (15ebd834564770a4df3c30ec6bd167d1)

1 / 68      (Adware)
hdvid-codec-chrome.exe  (ccba63341d44506ad074238f890a2c63)

1 / 68      (Adware)
j23zt297.exe  (1a0ee93a26b9c4ce90a8ddf926878b88)

41 / 68    (Adware)

19 / 68    (Adware)

1 / 68      (Adware)
gophoto.it v9.0-buttonutil64.dll  (1c7cacebb8f3e47ddf18a9259e1eae59)

43 / 68    (Adware)

45 / 68    (Adware)
gophoto.it v9.0-bg.exe (GoPhoto.it V9.0 by installdaddy)  (51b7297910db7e661466f72f4fabbce2)

1 / 68      (Adware)

1 / 68      (Adware)
fvbhruo3.exe  (fe80c9026e4e0904d7c0009b6bc3973b)

1 / 68      (Adware)
the_man_with_the_10_stone_testicles_hdtv_xvid-afg.exe  (51cd0be308bbee96b802b088fa78aea4)

1 / 68      (Adware)

38 / 68    (Adware)

1 / 68      (Adware)
hdvid_codec_chrome.exe  (9f51e6798f3e3c2660a961201ef148cc)

1 / 68      (Adware)

1 / 68      (Adware)
uninstall.exe  (675b4aa5bd59ea43b94ea639768cae7d)

1 / 68      (Adware)
gophoto.it v9.0-nova.dll  (ba1ab00e0d261c873c2579c10cc00fd6)

1 / 68      (Adware)
gophoto.it v9.0-buttonutil64.dll  (92050d66056052cef6469d3487e1f8aa)

43 / 68    (Adware)
gophoto.it v9.0-bho.dll (GoPhoto.it V9.0 by installdaddy)  (5cb170415fe96e8428f56dfdfa08dc8a)

1 / 68      (Adware)
l4n0v1c14r3b3ld3latdvdrip1965peliculasmascomavi.exe  (1fc10a50e0b8daf97b0e2a592d26c9e0)

1 / 68      (Adware)
fbb9938279c0aebcad1491cd5313a6ee_132992.npb  (fbb9938279c0aebcad1491cd5313a6ee)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

 
Latest 30 of 3,555 files

Downloads URLs for files signed by CoolMirage Ltd..

1 / 68      (Adware)

The certificates below are also signed by CoolMirage Ltd..

029E9B7F7CD982D1F52BA19EDA66E340  (Aug 26, 2014 to Nov 10, 2015)

2B95F61752266B15878ADF48E717C64B  (May 04, 2014 to Jun 07, 2015)

The following publishers (by Authenticode signature organization name) are related.

Remove CoolMirage Ltd. Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to CoolMirage Ltd. by Thawte, Inc. on June 06, 2013 with the serial number '110f603e63c86349a5f243ea06966f33'.