Natan Risman

Publisher Information

Natan Risman is a brand of publishers/developers run by WebPick Internet Holdings Ltd. located in Ramat Ha'Chayal Tel Aviv, Israel. The company is a primary distributor of unwanted software. Natan Risman is a developer of WebPick Internet Holdings and publishes a number of adware web browser plugins designed to monitor web browser behavior and inject advertisements (banner, popups, text-links, etc.) in the browser by using the WebPick InstalleRex monetization delivery platform. These programs from Natan Risman are typiclaly installed on a variety of names and misspellings and are very difficult to remove. According to WebPick, they use developers to sign their adware in order to "throw off competitors".
Authority:
COMODO CA Limited

Valid from:
6/6/2012 2:00:00 AM

Valid to:
6/7/2013 1:59:59 AM

Subject:
CN=Natan Risman, O=Natan Risman, STREET=Gordon 6, L=Tel Aviv, S=Israel, PostalCode=63407, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
34640f50a673f31e25ef247830cca289

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.WebPick.NatanRisman.Installer (M), Adware.WebPick.Installer (M)
100.00%

Malwarebytes
PUP.Optional.Installex, PUP.Optional.InstallRex
76.00%

IKARUS anti.virus
PUP.InstallRex
76.00%

Clam AntiVirus
Win.Adware.Agent-6651, Win.Trojan.742388, Win.Adware.Downware-591, Win.Adware.Application-425
76.00%

K7 AntiVirus
Trojan , Unwanted-Program
76.00%

K7 Gateway Antivirus
Trojan , Adware , Unwanted-Program
76.00%

Bkav FE
HW32.CDB, W32.FamVT.AntiFWK.Trojan
74.00%

nProtect
Trojan.Generic.9549828, Backdoor/W32.Clack.301504
74.00%

CMC Antivirus
Trojan.Win32.PEF13C!O, Adware.Win32.InstallMate!O
74.00%

Agnitum Outpost
Adware.Generic, Riskware.InstallMate, PUA.InstalleRex
74.00%

36 / 68    (Adware)
fastdownload.exe (Setup by Premium)  (dd52d33289e7076e915f7df0f673ab5b)

33 / 68    (Adware)
codec-v.exe (Setup by Premium)  (5bf8185759a670a6bf46a95bf922a8e5)

36 / 68    (Adware)
fastdownload.exe (Setup by Premium)  (e9011b80b2d03dc16035443b6afc12f8)

36 / 68    (Adware)
fastdownload.exe (Setup by Premium)  (1485fe80f08c87611efff6a5da30a4f7)

36 / 68    (Adware)
fastdownload.exe (Setup by Premium)  (55ad04e4c0c0f74b2170f53937b1cbfc)

35 / 68    (Adware)
downloadsetup.exe (Setup by Premium)  (0124e3a041d7ee48e54ba7b5ae39bd5e)

36 / 68    (Adware)
fastdownload.exe (Setup by Premium)  (9a28111eef7d8459929ed4c82bdd2324)

1 / 68      (Adware)
fastdownload.exe (Setup by Premium)  (fb2414b42c950062f1be7479f5a6189b)

1 / 68      (Adware)
fastdownload.exe (Setup by Premium)  (48519b3eab8110ef7442ad011e562353)

22 / 68    (Adware)
fastdownload.exe (Setup by Premium)  (e293470a275ba993519b016a8039895f)

44 / 68    (Adware)
setup.exe (StarApp)  (bc1bdcf1fa706f65eb05f985b96fedbe)

36 / 68    (Adware)
fastdownload.exe (Setup by Premium)  (7b70a9d9a0fe0e9ab1cd777bfafcc36c)

36 / 68    (Adware)
fastdownload.exe (Setup by Premium)  (20e13faf4340386ea4b7af245d6ba7d7)

1 / 68      (Adware)
halo font.exe (Setup by Premium)  (2d56af4294e05f96e16d3edc636d88da)

1 / 68      (Adware)
dodge font.exe (Setup by Premium)  (580720ba8597d9a67797a0d0905bc225)

35 / 68    (Adware)
downloadsetup.exe (Setup by Premium)  (67c480a80bdc0cd92d7e8c5262f9507b)

36 / 68    (Adware)
fastdownload.exe (Setup by Premium)  (17c14d1472d0217c2cf0f8b59f24718c)

36 / 68    (Adware)
fastdownload.exe (Setup by Premium)  (14205e1d7dc8fd8bfcdd60401cf8636c)

36 / 68    (Adware)
fastdownload.exe (Setup by Premium)  (66dad179c2c0b3f3f011b4b87d58ed90)

36 / 68    (Adware)
fastdownload.exe (Setup by Premium)  (519301179775a7b410efc2452906d5f7)

1 / 68      (Adware)
fastdownload.exe (Setup by Premium)  (af869d9727200512f02a435b7628034f)

1 / 68      (Adware)
fastdownload.exe (Setup by Premium)  (3c01f4a59a7cbeadd3d442cbc8026310)

1 / 68      (Adware)
gif animado.exe (Setup by Premium)  (d6cddbd2ab782d3b6577e0446eb04939)

36 / 68    (Adware)
fastdownload.exe (Setup by Premium)  (7bcca9b805729638557e223308e45086)

1 / 68      (Adware)
d5_bbdfpwjpl.rar.exe (Setup by Premium)  (41bc22742f7302d42bf1d301a558f361)

36 / 68    (Adware)
fastdownload.exe (Setup by Premium)  (173e59c8e84003233d17aa58173f4b84)

44 / 68    (Adware)
setup.exe (StarApp)  (cd215f6375cc99a0fa68094f707e7dcf)

36 / 68    (Adware)
fastdownload.exe (Setup by Premium)  (28c2c5d6fc7b76557010aeed4377ecd0)

36 / 68    (Adware)
fastdownload.exe (Setup by Premium)  (13afaa69b9bd2ed7331102e964c51bec)

36 / 68    (Adware)
fastdownload.exe (Setup by Premium)  (fd6cf3f0ff8f7594315c4c0826b882d9)

 
Latest 30 of 812 files

Downloads URLs for files signed by Natan Risman.

35 / 68    (Adware)
http://storagenl.info/.../  (downloadsetup.exe)

36 / 68    (Adware)
http://storagenl.info/.../  (fastdownload.exe)

The following publishers (by Authenticode signature organization name) are related.

* Note, the details and description above are based on the code signing digital signature issued to Natan Risman by COMODO CA Limited on June 06, 2012 with the serial number '34640f50a673f31e25ef247830cca289'.