EVROPLAST LLC

Publisher Information

EVROPLAST LLC is a software developer located in Donetsk, Alberta in Ukraine*. The company is a primary distributor of unwanted software. There is one additional code signing certificate issued to this publisher.
Authority:
thawte, Inc.

Valid from:
12/22/2014 1:00:00 AM

Valid to:
12/23/2015 12:59:59 AM

Subject:
CN=EVROPLAST LLC, O=EVROPLAST LLC, L=Donetsk, S=Alberta, C=UA

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
3a189ec1963ab0505c115175c20cd893

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.EVROPLAST.AA, PUP.Installer.EVROPLAST.Y, PUP.Installer.EVROPLAST.d, PUP.Installer.EVROPLAST.FF, PUP.Installer.EVROPLAST.Z, PUP.Installer.EVROPLAST.P, PUP.Amonetize.EVROPLAST.Bundler (M), PUP.Amonetize.EVROPLAS.Bundler (M), PUP.Amonetize (M)
100.00%

Dr.Web
Trojan.Amonetize.341
58.62%

Trend Micro House Call
Suspicious_GEN.F47V1230, TROJ_GEN.R047H07LU14, Suspicious_GEN.F47V1231, Suspicious_GEN.F47V1229
51.72%

McAfee
Artemis!9F87C5DEF20C, Artemis!1E10DD8F4D96, Artemis!AB171716F944, Artemis!54E117F334B4, Artemis!9EEAE81957CC, Artemis!F23EBE58EE48, Artemis!85D027E56623, Artemis!6D74EE3210A8
51.72%

ESET NOD32
Win32/Amonetize.CK (variant)
51.72%

Sophos
Generic PUA HM, Amonetize, PUA 'Amonetize'
51.72%

AhnLab V3 Security
PUP/Win32.Amonetiz
51.72%

Avira AntiVirus
Adware/Amonetize.576192.24, Adware/Amonetize.575680.15, Adware/Amonetize.576200.16, Adware/Amonetize.575168.46, Adware/Amonetize.575168.44
44.83%

avast!
Win32:Dropper-gen [Drp], Win32:Adware-gen [Adw], Win32:Malware-gen, Win32:PUP-gen [PUP]
44.83%

Fortinet FortiGate
Adware/Amonetize, Riskware/Amonetize
41.38%

1 / 68      (Adware)
media converter__2467_il13535.exe  (c08c53174155e202fdca3f1490e6b92f)

1 / 68      (Adware)
Setup.exe  (2eb8439230d8a9ae05f01cb38504ec47)

1 / 68      (Adware)

1 / 68      (Adware)
office 2013 proplus x86 x64 enus__7821_il57230.exe  (53773bd64cd876dbb66e854078a51608)

1 / 68      (Adware)
launcher__11002.exe  (ce29fda9de09ed0ca2819f4dabf16f1d)

1 / 68      (Adware)
flashplayersetup__11412_i1434848814_il75.exe  (edac85df455de6344d2ac7950afeca79)

1 / 68      (Adware)
7zipsetup__10793_i1438204571_il5905.exe  (6a8fab92bbdad87c848dddfe8802fb41)

1 / 68      (Adware)
{blocked}.exe  (2150a4f216f1240da24e81171d2e92c1)

1 / 68      (Adware)
bubblegums__5008_il1166462.exe  (4889513a6c2fb57ff7f8feeec11dc0f8)

1 / 68      (Adware)
flashplayer__10155_i1434930586_il7.exe  (0d1b30965859b3b685ffddc88b73b737)

1 / 68      (Adware)
youtubedownloaderpro__6090_i1434916650_il145288.exe  (849b60305824bb58341fd8e3842c3ac7)

1 / 68      (Adware)

17 / 68    (Adware)

16 / 68    (Adware)
launcher__11002.exe  (0bc424ae5b522791725722dceff55511)

11 / 68    (Adware)

14 / 68    (Adware)
00000000  (6d74ee3210a89328aa454a10481d0a49)

11 / 68    (Adware)

25 / 68    (Adware)
launcher__11002.exe  (182e01690144cec8f7190d447b4c0c42)

6 / 68      (Adware)
mediaplayer__9220_i1434406542_il513.exe  (85d027e56623dd286876d5895fbfda03)

6 / 68      (Adware)
mediaplayer__9220_i1434336700_il513.exe  (19f1ff04d9f75c189a49e1d4c9c7e2e2)

12 / 68    (Adware)
serialkeygen__7934_il1058553.exe  (feb4191cfe9e3cbfc87ddf73749b17b9)

6 / 68      (Adware)
mediaplayer__3137_il94.exe  (1aad81c5b4db33c7985ac55b2023ea57)

10 / 68    (Adware)

14 / 68    (Adware)
story weaver__10924_i1436242136_il855133.exe  (2e68a4acc91ba4e7eac00eedd151ec80)

12 / 68    (Adware)
removewat3__7934_il610165.exe  (9eeae81957ccbe5273beaf7e030c3c3a)

12 / 68    (Adware)
vlcmediaplayersetup__11070_il94.exe  (54e117f334b40091d6a6718ef1378575)

12 / 68    (Adware)
mediaplayer__9220_i1435452283_il513.exe  (803116515e49d867fcdafab51ef8d80e)

12 / 68    (Adware)
mediaplayer__3936_il1857.exe  (1e10dd8f4d96947c9e203ec9462337d1)

12 / 68    (Adware)
file.downloader__9581_il263.exe  (9f87c5def20cf9fa9d4ea09f18820cb5)

Downloads URLs for files signed by EVROPLAST LLC.

12 / 68    (Adware)

6 / 68      (Adware)

10 / 68    (Adware)

10 / 68    (Adware)
http://letshareus.com/download.php?aff=10451&name=wpman&file=Download.Setup  (heroes and generals hack october 2014 no survey no password__10967_i1436325746_il311680.exe)

10 / 68    (Adware)

11 / 68    (Adware)

6 / 68      (Adware)

12 / 68    (Adware)
http://goo.gl/3xD03U  (file.downloader__9581_il263.exe)

12 / 68    (Adware)

12 / 68    (Adware)

6 / 68      (Adware)

6 / 68      (Adware)

10 / 68    (Adware)
http://hqhub.net/download_player.php?a=97600&f=1  (heroes and generals hack october 2014 no survey no password__10967_i1436325746_il311680.exe)

10 / 68    (Adware)
http://letshareus.com/download.php?aff=10892&name=fbchat&file=Download Game Onet 2 For PC Windows Xp 7 8 dan 9 Gratis  (heroes and generals hack october 2014 no survey no password__10967_i1436325746_il311680.exe)

10 / 68    (Adware)
http://download-cdn.com/direct/.../mediaplayer_setup.php?a=12355&s=0&t=1&fv=7  (heroes and generals hack october 2014 no survey no password__10967_i1436325746_il311680.exe)

10 / 68    (Adware)
http://fixdownloadz.com/4/download.php?i=37&soft_name=PSG Update&soft_version=2.57&soft_url=https://.../gws=57_445526Ps  (heroes and generals hack october 2014 no survey no password__10967_i1436325746_il311680.exe)

10 / 68    (Adware)
http://myfreedownloadsnow.com/download_direct.php?id=1592&name=file381112  (heroes and generals hack october 2014 no survey no password__10967_i1436325746_il311680.exe)

 
Latest 30 of 122 download URLs

The following websites host and distribute files published by EVROPLAST LLC.

30 of 31 domains

The following certificate is also signed by EVROPLAST LLC.

54306BD964BEDB84E36595E6748114EA  (Nov 19, 2014 to Nov 20, 2015)

The following publishers (by Authenticode signature organization name) are related.

30 of 92 publishers

* Note, the details and description above are based on the code signing digital signature issued to EVROPLAST LLC by thawte, Inc. on December 22, 2014 with the serial number '3a189ec1963ab0505c115175c20cd893'.