Dennis Nazarenko

Publisher Information

Dennis Nazarenko is a brand of publishers/developers run by WebPick Internet Holdings Ltd. located in Ramat Ha'Chayal Tel Aviv, Israel. The company is a primary distributor of unwanted software. Dennis Nazarenko is a developer of WebPick Internet Holdings and publishes a number of adware web browser plugins designed to monitor web browser behavior and inject advertisements (banner, popups, text-links, etc.) in the browser by using the WebPick InstalleRex monetization delivery platform. These programs from Dennis Nazarenko are typiclaly installed on a variety of names and misspellings and are very difficult to remove. According to WebPick, they use developers to sign their adware in order to "throw off competitors". There is one additional code signing certificate issued to this publisher.
Remove Dennis Nazarenko Malware - Powered by Reason Core Security
Authority:
The USERTRUST Network

Valid from:
11/2/2008 1:00:00 AM

Valid to:
11/3/2009 12:59:59 AM

Subject:
CN=Dennis Nazarenko, O=Dennis Nazarenko, POBox=15A, STREET=Jovtneva 7A, L=Vishneve, S=Kievskaya, PostalCode=08132, C=UA

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
009ca1956f3a54a095ba9d02bc02272cfa

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.DennisNazarenko.J, PUP.Startup.DennisNazarenko.O, PUP.DennisNazarenko.M, PUP.DennisNazarenko.K, PUP.DennisNazarenko.O, PUP.DennisNazarenko.F, PUP.DennisNazarenko.V, PUP.DennisNazarenko.N, PUP.Installer.DennisNazarenko.Z, PUP.Installer.DennisNazarenko.c, PUP.Bundler.WebPick, Threat.WebPick.Bundler, PUP.WebPick.Bundler, PUP.WebPick.DennisNazarenko.Bundler (M)
100.00%

ByteHero BDV
Trojan.Win32.Heur.Gen
5.00%

Avira AntiVirus
TR/Dropper.Gen
5.00%

ESET NOD32
Detection.Undefined
5.00%

1 / 68      (Adware)

1 / 68      (Adware)
unins000.exe  (74a6ec3e6bc8d3996f2c9cb0b99eb0be)

1 / 68      (Adware)

1 / 68      (Adware)

3 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
tidyfavoritiesservice.exe  (d802b1fd00031554bfb5686916b25839)

1 / 68      (Adware)
TidyFavorites.exe (Tidy Favorites by OrdinarySoft)  (d360c47d0a87e96cbd89ba0208f4d278)

1 / 68      (Adware)
installbrowserbuttons.exe  (342651119cfd64cd0a34c06669cadde3)

1 / 68      (Adware)
run64.exe (Vista Start Menu by OrdinarySoft)  (08eb3db5959a9251ca4abcede11da8a4)

1 / 68      (Adware)
vistastartmenu.exe (Vista Start menu by OrdinarySoft)  (be711b0b326c2cb36658d012a0c3e28c)

1 / 68      (Adware)
vistastartmenu.dll (Vista Start Menu by OrdinarySoft)  (8976be4da90e8911bd11b0a5dede17d3)

1 / 68      (Adware)
qUninstall.dll (Quick Uninstall by OrdinarySoft)  (447bbb966335066770d6e8ceb368959e)

1 / 68      (Adware)
vistahookapp.exe (Vista Start Menu by OrdinarySoft)  (b79fb2d6a2d956d65f26ef2ce36884ab)

2 / 68      (Adware)
vistastartmenu.exe (Vista Start menu by OrdinarySoft)  (aa8b9f0d9bb96ba8422b29d0a5780924)

1 / 68      (Adware)
vistahookdll.dll (Vista Start Menu by OrdinarySoft)  (8db45c44d29f8639c0dcb14d5087b2c8)

The following certificate is also signed by Dennis Nazarenko.

00DBE65D78CE895A82ADCC70F584A6A0BB  (Nov 02, 2007 to Nov 02, 2008)

Remove Dennis Nazarenko Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to Dennis Nazarenko by The USERTRUST Network on November 02, 2008 with the serial number '009ca1956f3a54a095ba9d02bc02272cfa'.