Eli Dahan

Publisher Information

Eli Dahan is a brand of publishers/developers run by WebPick Internet Holdings Ltd. located in Ramat Ha'Chayal Tel Aviv, Israel. The company is a primary distributor of unwanted software. Eli Dahan is a developer of WebPick Internet Holdings and publishes a number of adware web browser plugins designed to monitor web browser behavior and inject advertisements (banner, popups, text-links, etc.) in the browser by using the WebPick InstalleRex monetization delivery platform. These programs from Eli Dahan are typiclaly installed on a variety of names and misspellings and are very difficult to remove. According to WebPick, they use developers to sign their adware in order to "throw off competitors".
Authority:
COMODO CA Limited

Valid from:
6/9/2013 8:00:00 PM

Valid to:
6/10/2014 7:59:59 PM

Subject:
CN=Eli Dahan, O=Eli Dahan, STREET=Halapid 3, L=Ramat Gan, S=Center, PostalCode=52573, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00864002c7281b93c1609931176b93a6ae

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
Threat.Installer.EliDahan, Adware.AdInjector.Installer, PUP.EliDahan, Adware.EliDahan.Installer (M), PUP.EliDahan.Installer (M), PUP.WebPick.EliDahan (M), PUP.WebPick.EliDahan.Installer (M), Adware.WebPick.Installer (M), PUP.WebPick.EliDahan.Bundler (M)
100.00%

avast!
Win32:InstalleRex-Z [PUP], Win32:InstalleRex-DS [PUP], Win32:InstalleRex-Y [PUP], Win32:Adware-AYT [PUP], Win32:InstalleRex-AI [PUP]
44.00%

Dr.Web
Adware.Downware.1442, Adware.Downware.1166, Adware.Downware.1541
38.00%

VIPRE Antivirus
Threat.4753027, Installerex/WebPick, WebPI
38.00%

McAfee
PUP-FDX, Program.PUP-FHQ, PUP-FHQ!CDDCEAE2695D, PUP-FDX!BC73ABE5957E
38.00%

Kaspersky
not-a-virus:HEUR:Downloader.Win32.AdLoad, not-a-virus:AdWare.Win32.Agent, Trojan.Win32.AntiFW
38.00%

Malwarebytes
PUP.Optional.Installrex, PUP.Optional.Installex, PUP.Optional.InstalleRex
38.00%

K7 Gateway Antivirus
Unwanted-Program , Riskware
38.00%

NANO AntiVirus
Riskware.Win32.Downware.crfmjd, Riskware.Win32.Downware.crdwiu, Riskware.Win32.Agent.crfilc, Riskware.Win32.Downware.crfmio
38.00%

Comodo Security
Application.Win32.InstalleRex.KG, Application.Win32.Agent.W
38.00%

1 / 68      (Adware)
SE.exe (SE by SkypEmoticons)  (426be9c35df2587b344792f994bd016b)

1 / 68      (Adware)
fm0hhzcx.exe (SummerSoft)  (ea5fdab7642a6539f6929fb4d48c7b10)

1 / 68      (Adware)
cbq_hd0s.exe (SummerSoft)  (714c1ba0b365e3cec5ad5c9d05bdffed)

1 / 68      (Adware)
piersi - bałkanica (kalwi.exe (StarApp)  (91d89584e916f6ac07b153283af9858a)

1 / 68      (Adware)
microsoft office 2013 serial keygen.exe (SummerSoft)  (0b35b9e78dc14da51a769d30139f148a)

1 / 68      (Adware)
ssetup-se.exe (SkypEmoticons)  (bd3f26fc52603b32cd7f922dbc8ef76c)

39 / 68    (Adware)
download.exe (StarApp)  (784cf3a842c4d02c779825b63af128fb)

1 / 68      (Adware)
download.exe (StarApp)  (7530619ad008a97779fac8b0db330c6a)

1 / 68      (Adware)
download.exe (StarApp)  (616ac1b4a77a14868d54bc8595a0f87c)

36 / 68    (Adware)
download.exe (SummerSoft)  (53d5954cecb57b7aca1a325284020ad1)

1 / 68      (Adware)
bagas31 - limbo v.0.1.rar.001.exe (StarApp)  (776cb9722b1e26647dc1f1e84476064a)

1 / 68      (Adware)
trzf2ca.tmp (SkypEmoticons)  (a84d9463551a37cff8ab3a7b02900aea)

1 / 68      (Adware)
trz6ec2.tmp (SkypEmoticons)  (61f3166255336e5f82aa103571fdc873)

1 / 68      (Adware)
amnesia the dark descent-skidrow.exe (StarApp)  (443a9caef878b10bca58fef7331c4de5)

36 / 68    (Adware)
download.exe (SummerSoft)  (a8ae736b36ffec4b59d2263d3d489e20)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
manhattan.exe (SummerSoft)  (0c24c83b2fef6a0a1b6e34ff6c5f846c)

36 / 68    (Adware)
download.exe (SummerSoft)  (0b505a1e13db8c98772557cf76e955fd)

1 / 68      (Adware)
t_tqvnwt.exe (StarApp)  (4ecab72a238fdbbc5910822a19f6f4f7)

36 / 68    (Adware)
download.exe (SummerSoft)  (5a93036cc1645415c73d7365e5a695cc)

36 / 68    (Adware)
download.exe (SummerSoft)  (9a4ca83320df1f9b7cdfba4bb3f0917b)

1 / 68      (Adware)
yq2iglbt.exe (SummerSoft)  (1db3ccd090da29b312558b443405cf6a)

1 / 68      (Adware)
d_8tzhpi.exe (SummerSoft)  (9de5441b76ad4bc4508c73cc828d1a01)

36 / 68    (Adware)
download.exe (SummerSoft)  (5e04279bc7931a09fd5bd1f87ca29194)

1 / 68      (Adware)
download.exe (SummerSoft)  (71a26a5d24fd0a7b2136ef63858fbd63)

1 / 68      (Adware)
yibhvp4z.exe (SummerSoft)  (69b356e95c669d7ce12419b412a0ebad)

1 / 68      (Adware)
evpuxt44.exe (SummerSoft)  (4726f6d1ba29706ae96928a5cb5ccb13)

1 / 68      (Adware)
dyhg9cjf.exe (SummerSoft)  (4ff064e4fd837e074a4a75fa54732966)

1 / 68      (Adware)
amxdmvb9.exe (SummerSoft)  (2ac42f8013f8cba5b9ef75656ab9bfa3)

 
Latest 30 of 119 files

Downloads URLs for files signed by Eli Dahan.

1 / 68      (Adware)

The following publishers (by Authenticode signature organization name) are related.

* Note, the details and description above are based on the code signing digital signature issued to Eli Dahan by COMODO CA Limited on June 09, 2013 with the serial number '00864002c7281b93c1609931176b93a6ae'.