OOO

Publisher Information

OOO is a software publisher located in Ekaterinburg, Sverdlovskaya Obl. in Russia*. The company is a primary distributor of unwanted software. Thre are 79 additional code signing certificates issued to this publisher.
Authority:
COMODO CA Limited

Valid from:
3/16/2016 3:00:00 AM

Valid to:
3/17/2017 2:59:59 AM

Subject:
CN="OOO ""LIDER-PRO""", O="OOO ""LIDER-PRO""", STREET="kosmonavtov p-t, 18, Ь, 11", L=Ekaterinburg, S=Sverdlovskaya obl., PostalCode=620017, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00c1fb6687a3a053ae6900b6e0148a6366

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP (M)
100.00%

Dr.Web
Trojan.LoadMoney.1366, Trojan.DownLoader21.34071
21.05%

ESET NOD32
Win32/Slugin.A virus, Win32/RuKometa.X potentially unwanted application
15.79%

F-Secure
Win32.SlugIn.A
10.53%

avast!
Win32:Patched-JI
10.53%

F-Prot
W32/Slugin.B
10.53%

McAfee
Virus.W32/Wplugin
10.53%

Emsisoft Anti-Malware
Win32.SlugIn
10.53%

Microsoft Security Essentials
Threat.Undefined
10.53%

Kaspersky
Virus.Win32.Slugin
10.53%

1 / 68      (Adware)
dtk5fmzwcbuy.exe  (8ef0f4157d056209566c8187d982707b)

1 / 68      (Adware)
syslog.exe.120220.gzquar  (be4bd60c4b203026f43ebb262bd03e23)

1 / 68      (Adware)
panozlt1zx4r.exe  (fa2f9e6e54fee68286f9b9f90f1aac18)

3 / 68      (Adware)
comdev.exe  (6b2b3dcc60e78b9c1e140dce42f284bd)

4 / 68      (Adware)
e.exe  (65ccd1dd2f88d80f69c75fc08dc207ab)

1 / 68      (Adware)
e.exe  (5140a7c9d659df1e9296ad60ed81a8e6)

1 / 68      (Adware)
svshost.exe  (c977e99ea59815e497f81ee5bac5c94a)

1 / 68      (Adware)
asmycrvszpiu.exe  (ead617da5b8abc1eba1efbe3f1f4c14f)

1 / 68      (Adware)
powermonitor.exe  (5140a7c9d659df1e9296ad60ed81a8e6)

1 / 68      (Adware)
ni.exe  (937ed88a92a7f8ec50aeaac2f9d40b38)

1 / 68      (Adware)
svshost.exe  (202506a293beaca1c37e43b64f57b257)

1 / 68      (Adware)
5fze75pz1gia.exe  (398a84234247f0651d1a5c19d5d82d2c)

1 / 68      (Adware)
syslog.exe  (a49221e441a3ada499ee4d15359664a2)

1 / 68      (Adware)
tmp00000020fe4771024ae9d61a  (2c25a62a013604c75398fe7027f66d0e)

1 / 68      (Adware)
svshost.exe  (cc640ba0f3abffe8a25f42bddfba4c15)

12 / 68    (Adware)
bnsl8ytvxcve.exe  (20340d5d883f5df172a56a1d8e52d0fe)

11 / 68    (Adware)
2rzfhswxm7r7.exe  (dc75d0636f28391430d414baff37aa0f)

1 / 68      (Adware)
s.exe  (1a48ed4593d3d713dbcd37cb9fb0ca17)

1 / 68      (Adware)
filesystemdriver.exe  (cc640ba0f3abffe8a25f42bddfba4c15)

Downloads URLs for files signed by OOO .

1 / 68      (Adware)
http://browser4update.ru/n.exe  (cc640ba0f3abffe8a25f42bddfba4c15)

The following websites host and distribute files published by OOO .

The certificates below are also signed by OOO .

09C2413E3B0CACE3E855A2C1A5CADBD6  (Mar 07, 2016 to Mar 08, 2019)

00E706CCD87DA6065486B42C0646C2DBF9  (Feb 11, 2016 to Feb 10, 2019)

5F5A06A7374A1B0B8DD3B08620FB7E8F  (Nov 27, 2015 to Dec 19, 2018)

009B0833F8AD9F393DF6B1E28AD4D38F9E  (Jun 09, 2016 to Jun 10, 2018)

00E2D0DD88AA54AE6A33646C36CF01E955  (Mar 23, 2015 to Mar 23, 2018)

6A96EA380826A911F2E88338A7053400  (Oct 18, 2016 to Oct 19, 2017)

00B526F3AAE3DA60C05A2E941DBACDBFF2  (Sep 28, 2016 to Sep 29, 2017)

79DB1629A125B1CDAA6C39B8A0B7360E  (Nov 09, 2016 to Sep 29, 2017)

00B633A6D77942DEBFF38D2DA2ABA75A23  (Jan 09, 2017 to Sep 01, 2017)

00BC4D5469B576BF5C92276B809D9303A6  (Aug 29, 2016 to Aug 30, 2017)

10 of 79 code signing certificates issued

The following publishers (by Authenticode signature organization name) are related.

* Note, the details and description above are based on the code signing digital signature issued to OOO by COMODO CA Limited on March 16, 2016 with the serial number '00c1fb6687a3a053ae6900b6e0148a6366'.