OOO Russkie Internet Reshenija

Publisher Information

OOO Russkie Internet Reshenija is a software publisher located in Moscow, Russia*. The publisher primarily developes software that can be classified as adware. Thre are 2 additional code signing certificates issued to this publisher.
Remove OOO Russkie Internet Reshenija Malware - Powered by Reason Core Security
Authority:
Thawte, Inc.

Valid from:
12/29/2012 4:00:00 AM

Valid to:
2/28/2015 3:59:59 AM

Subject:
CN=OOO Russkie Internet Reshenija, OU=IT Department, O=OOO Russkie Internet Reshenija, L=Moscow, S=Moscow, C=RU

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
70e974f1d705599bd16fe4cfa4da84a9

Scanner detections:
Detections  (86% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.OOORusskieInternetReshenija, Common.OpenSSLPackaged.PUP, Common.PUP.OOORusskieInternetReshenija, PUP.Installer.OOORusskieInternetReshenija, PUP.OOORusskieInternetReshenija (M), Common.OpenSSLPackaged.PUP.OOORusskieInternetReshenija (M), Common.PUP.OOORusskieInternetReshenija (M), Common.CRuntimePackaged.PUP.OOORusskieInternetReshenija (M), PUP.OOORusskieInternetReshenija.Installer (M)
100.00%

F-Prot
W32/Downloader-Web-based!Maximu
6.00%

Commtouch SDK
W32/Downloader-Web-based!Maximu
6.00%

ByteHero BDV
Trojan.Malware.Obscu.Gen.001
6.00%

Trend Micro House Call
TROJ_GEN.F47V0401, TROJ_GEN.R0CBH01H513
4.00%

Comodo Security
Heur.Packed.Unknown
2.00%

1 / 68      (PUP)
unins000.exe  (ed80bae38e0d7323a5fca4b5f9ebef55)

1 / 68      (PUP)
qip2012.exe (QIP 2012 by QIP.ru)  (edbd7c2cb4dd503d9adfc4b66d6cfe5e)

1 / 68      (PUP)
updater.exe (QipGuard updater by QIP.ru)  (6c88cfda0e4ba8a90f760497bfbc7a63)

1 / 68      (PUP)
chrome.dll  (e32b9317bfc8a2654c6c752998cd422d)

2 / 68      (PUP)
unins000.exe  (011c9efbdab56476f3b32ea01488ec28)

1 / 68      (PUP)

1 / 68      (inconclusive)
MSVCR90.DLL (Microsoft Visual Studio 2008 by Microsoft)  (aa687789a7f4fc757298dcf1b085e4d4)

1 / 68      (inconclusive)
MSVCP90.DLL (Microsoft Visual Studio 2008 by Microsoft)  (de14499f6fe4b982dbcb2aae140c7c1e)

1 / 68      (PUP)
dsfvorbisencoder.dll  (313a57d652f3089d96ddef5e361a9764)

1 / 68      (PUP)
dsfvorbisdecoder.dll  (3381727d7a5f3e2a1ff10f39194066f4)

1 / 68      (PUP)
dsfoggmux.dll  (be2e42a15533eea2f57409ad8b10d6e0)

1 / 68      (PUP)
dsfoggdemux2.dll  (6167dd0fd66a231f714e71b9d77597f0)

1 / 68      (PUP)
xmpp.dll  (a77072ea7398a0a5e02f0b74ca1743c8)

1 / 68      (inconclusive)

1 / 68      (inconclusive)

1 / 68      (PUP)

1 / 68      (PUP)
helper.dll  (1c16b5d016c95e09330af199ba9f3118)

1 / 68      (PUP)
chsdet.dll (Charset detector)  (976751ad163273490251204a845cf5e4)

2 / 68      (PUP)
unins000.exe  (eac1d23abbd85d17b26fba0b47a48608)

1 / 68      (PUP)

1 / 68      (PUP)
4talk.exe (4talk by Russian Internet Solutions)  (ba4850bb12ef5b91dff25988c42f9e98)

1 / 68      (PUP)
qipguard.exe (QIP Internet Guardian by QIP.ru)  (d44488fddf7704c4256dfd1187ab3a61)

1 / 68      (PUP)
qipguard.exe (QIP Internet Guardian by QIP.ru)  (85fa12ab72025d8dc3833d0825839e1d)

2 / 68      (PUP)
unins000.exe  (a9d48ab33e5e316293cdd070d6ceda33)

3 / 68      (PUP)
qip_rambler.exe (QIP 2012 by QIP.ru)  (cbc7e6469c43aa3b87b460bb0374fd52)

1 / 68      (PUP)
infiumdetect.dll  (22930a06ed314724ef5268b16b7317ca)

1 / 68      (PUP)
unins000.exe  (23f9a61d75a8a16f9c2033e48c2966ff)

1 / 68      (PUP)
unins000.exe  (da9d2e62c3ff46960e58cb3ff0608388)

4 / 68      (PUP)
qip2012.exe (QIP 2012 by QIP.ru)  (94ed461a62ff6f30f643e8c06a878436)

1 / 68      (PUP)
unins000.exe  (cc936aba03fb6fee1fc70bb00bf0f863)

 
Latest 30 of 173 files

Downloads URLs for files signed by OOO Russkie Internet Reshenija.

3 / 68      (PUP)
http://download.qip.ru/.../qip2012.exe  (321e8417a04ed93e6e1120099a8fb238)

4 / 68      (PUP)
http://download.qip.ru/.../qip2012_nosms_8921.exe  (94ed461a62ff6f30f643e8c06a878436)

The following websites host and distribute files published by OOO Russkie Internet Reshenija.

The certificates below are also signed by OOO Russkie Internet Reshenija.

4D3719C982A3F74F3C5017CA380E9B3B  (Nov 18, 2010 to Jan 17, 2013)

01E694F0EE33389EFA689F9AAF6C8359  (Dec 11, 2009 to Dec 12, 2010)

Remove OOO Russkie Internet Reshenija Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to OOO Russkie Internet Reshenija by Thawte, Inc. on December 29, 2012 with the serial number '70e974f1d705599bd16fe4cfa4da84a9'.