Pass Revelator

Publisher Information

Pass Revelator is a software publisher located in PARIS, Outside United States in France*. The company is a primary distributor of unwanted software. There is one additional code signing certificate issued to this publisher.
Remove Pass Revelator Malware - Powered by Reason Core Security
Authority:
COMODO CA Limited

Valid from:
10/16/2013 5:00:00 PM

Valid to:
10/17/2015 4:59:59 PM

Subject:
CN=Pass Revelator, O=Pass Revelator, STREET=12 rue de Bercy, L=PARIS, S=Outside United States, PostalCode=75012, C=FR

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00d37b33cfac6554ac36a251fa8f91f977

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.PassRevelator.Y, PUP.Installer.PassRevelator.R, PUP.Installer.PassRevelator.U, PUP.PassRevelator.Z, PUP.PassRevelator.M, PUP.PassRevelator.I, Threat.Installer.PassRevelator, PUP.PassRevelator.Installer (M)
100.00%

Trend Micro House Call
HKTL_PASSREVEAL, TROJ_GEN.F47V1128, TROJ_GEN.F47V0403, TROJ_GEN.F47V0406, TROJ_GEN.F47V0529, ADW_DOWNWARE, Suspicious_GEN.F47V0707, Suspicious_GEN.F47V0625, Suspicious_GEN.F47V0611
61.76%

Kaspersky
not-a-virus:Downloader.Win32.Agent
52.94%

Qihoo 360 Security
Malware.QVM20.Gen, Win32/Virus.Downloader.629
47.06%

Bkav FE
W32.GazaneW.Trojan
32.35%

Dr.Web
Trojan.SMSSend.4486, BackDoor.Infector.133, Trojan.SMSSend.5362
20.59%

Quick Heal
Downloader.Agent.g3 (Not a Virus), Downloader.Agent.r5 (Not a Virus)
20.59%

VIPRE Antivirus
Pass Revelator, Trojan.Win32.Generic
17.65%

ESET NOD32
Win32/Somoto, Win32/RiskWare.PSWTool.PassRevelator
14.71%

Kingsoft AntiVirus
Win32.Troj.DownAgent.bw.(kcloud), Win32.Troj.Undef.(kcloud)
14.71%

1 / 68      (Adware)

1 / 68      (Adware)
{blocked}.exe (Pass Breaker Setup)  (4a7a8538a85a020b60d796796f48c254)

1 / 68      (Adware)

1 / 68      (Adware)
{blocked}.exe  (e751a3df5a8b4f0c98135060bd940aef)

5 / 68      (Adware)
{blocked}.exe (Pass Breaker Setup by Pass Revelator)  (72b9a091fb1410fc2358297b84374a01)

2 / 68      (Adware)
{blocked}.exe  (24a977c82619a4a53c3edcb32074fbaf)

5 / 68      (Adware)
{blocked}.exe (Pass Breaker Setup by Pass Revelator)  (61dc210ae8a4731c846a52221e021573)

3 / 68      (Adware)
{blocked}.exe (Pass Access Setup)  (2fcec61c4fd4c51da244565297459e2a)

5 / 68      (Adware)
system.data.sqlite.dll (System.Data.SQLite)  (85081b52f039f9cb004a6ecb3f89f9c1)

5 / 68      (Adware)

6 / 68      (Adware)

5 / 68      (Adware)

4 / 68      (Adware)

4 / 68      (Adware)
nssckbi.dll  (6dba802bb841cd2074a566e5dd1face7)

6 / 68      (Adware)

4 / 68      (Adware)

4 / 68      (Adware)

4 / 68      (Adware)

9 / 68      (Adware)
{blocked}.exe (Pass Finder by Pass Revelator)  (f1955c1effd915fd91186cfbbd94ef50)

13 / 68    (Adware)
{blocked}.exe  (292512373cb99bccf09fce9036a5a118)

10 / 68    (Adware)
{blocked}.exe (Installation de Pass Finder)  (19771dc3de85836e6f0847310d9a919c)

3 / 68      (Adware)
{blocked}.exe  (1e3e9be5064d8ccdc7d5aea12ffb6cf8)

16 / 68    (Adware)
{blocked}.exe (Pass Finder Setup)  (23b4aa4ac1e560b612ec1d5c004cf67b)

16 / 68    (Adware)
{blocked}.exe (Pass Finder Setup)  (39fff3f6224fc046c57771fc5d4d46a2)

1 / 68      (Adware)
infotrig.exe  (e3589955345fb313119a7d8449cc7a49)

1 / 68      (Adware)

3 / 68      (Adware)
{blocked}.exe (Pass Finder Setup by Pass Revelator)  (6b69354931710b3c37ac3a464c4f3620)

3 / 68      (Adware)

3 / 68      (Adware)
anti-robot_security_code.exe  (81fefdf47bf15c574e365f88017faada)

4 / 68      (Adware)
{blocked}.exe (Pass Finder Setup by Pass Revelator)  (2f8484f4ee4c920da514bae47f5a8dca)

 
Latest 30 of 34 files

The following certificate is also signed by Pass Revelator.

294C0252ECCFBDBA19C238FA705964F3  (Aug 11, 2014 to Oct 17, 2015)

Remove Pass Revelator Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to Pass Revelator by COMODO CA Limited on October 16, 2013 with the serial number '00d37b33cfac6554ac36a251fa8f91f977'.