Everstrike OOO

Publisher Information

Everstrike OOO is a software publisher located in Ulyanovsk, Russia*. The company is a primary distributor of unwanted software. Thre are 3 additional code signing certificates issued to this publisher.
Remove Everstrike OOO Malware - Powered by Reason Core Security
Authority:
VeriSign, Inc.

Valid from:
12/29/2011 1:00:00 AM

Valid to:
1/13/2013 12:59:59 AM

Subject:
CN=Everstrike OOO, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Everstrike OOO, L=Ulyanovsk, S=Ulyanovsk, C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
641e267f3d0313eeed9d86e2c36b2260

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.EverstrikeOOO, PUP.EverstrikeOOO (M), PUP.EverstrikeOOO.Installer (M), PUP.Everstrike (M), PUP.Everstrike.Installer (M)
100.00%

Avira AntiVirus
W32/Renamer.A, W32/Ramnit.C
4.00%

ByteHero BDV
Trojan.Malware.Win32.xPack.i
2.00%

Clam AntiVirus
Trojan.Agent-304004
2.00%

1 / 68      (Adware)
passwd.exe (by Everstrike Software)  (4b3044275915fe246ef658b49833b1e8)

1 / 68      (Adware)
LF30.exe (by Everstrike Software)  (0652fdf81790fa89de2029d8220e79da)

1 / 68      (Adware)
lang1.dll  (a65ce2093a7644130c03d1042c043b48)

1 / 68      (Adware)
lockfldr-ru.exe  (4200e5013edec82ad89d508b606bbae7)

1 / 68      (Adware)

1 / 68      (Adware)
USPro.exe (Universal Shield by Everstrike Software)  (8776d9daecaa5c63078a68ce27f41a17)

1 / 68      (Adware)
unlock.exe  (b86275882adb893b6f0ebb358cec6053)

1 / 68      (Adware)

1 / 68      (Adware)
installfl.exe (PF/FCP by Everstrike Software)  (1cc464cc5fd5114d46a81d4ad7a07eea)

1 / 68      (Adware)

1 / 68      (Adware)
decrypt.exe  (d197e591ec0e2cbca98e9a077229a526)

1 / 68      (Adware)
protectfolder64.dll  (57b59e8695113be4c992db1af47d0940)

1 / 68      (Adware)

1 / 68      (Adware)
exescripteditor.exe (ExeScript Editor)  (4d3c693a2835d4252f814b1575b66f70)

1 / 68      (Adware)
english.dll (ExeScript by Everstrike Software)  (acc0908e1555175715e4ceca63e616f5)

1 / 68      (Adware)
HF.exe (Hide Folder by Everstrike Software)  (7fbc0d12f564c371c031c1c74cd64b23)

1 / 68      (Adware)
ExeToService.exe (Exe To Service by Everstrike Software)  (e7908a7b1fd1540260f8f0b9255d689a)

1 / 68      (Adware)
exetoservice.exe (ExeToService)  (12d69e3b587c1dd8ee3c9d1a2b74d989)

1 / 68      (Adware)
run.exe  (941f5c95807d149e2406d20b907df24b)

1 / 68      (Adware)
ExeScript.exe (ExeScript by Everstrike Software)  (068fe7009aa9cf4b9c1cc9e912ad74ef)

1 / 68      (Adware)
english.dll (ExeScript by Everstrike Software)  (239879fbce51fb5e92bd3dbcdf26326c)

1 / 68      (Adware)
crshrpt.exe  (e966cc2b81f9a1a94c5ced6eaeb95440)

1 / 68      (Adware)
fcp.exe  (797d76b17df950ecf92facd4df6ab4c8)

1 / 68      (Adware)

1 / 68      (Adware)
fcp64.dll  (3795e4d97c1409c587553e0eeac3b01f)

1 / 68      (Adware)
ucenter.dll  (aadb7a9d2acf5dfe14cb850e418c9f77)

1 / 68      (Adware)
lfsys64.sys (Lock Folder XP by © Everstrike Software)  (19e934edfb6ea6311af41a653643fa5a)

1 / 68      (Adware)
_isuser.dll  (94791565db485610662685da587947a2)

1 / 68      (Adware)
_isuser.dll  (dd44301e16ca84dab763ec6c6670db5d)

1 / 68      (Adware)
lang9.dll  (4d1c831712c8ea9c7d7a95b03c9cbe29)

 
Latest 30 of 128 files

The certificates below are also signed by Everstrike OOO.

49A93C592149572F4142F301F1998E04  (Jan 15, 2013 to Feb 15, 2014)

1C6FEBAF7115A5C4FFAEAACEC3EA4FF1  (Dec 17, 2010 to Jan 14, 2012)

4F047BCF18A6FDD97F5D03D2A61289D8  (Jan 21, 2010 to Jan 13, 2011)

Remove Everstrike OOO Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to Everstrike OOO by VeriSign, Inc. on December 29, 2011 with the serial number '641e267f3d0313eeed9d86e2c36b2260'.