Philipp B. Winterberg

Publisher Information

Philipp B. Winterberg is a software developer located in Münster, Nrw in Germany*. The company is a primary distributor of unwanted software.
Remove Philipp B. Winterberg Malware - Powered by Reason Core Security
Authority:
COMODO CA Limited

Valid from:
3/29/2012 8:00:00 PM

Valid to:
3/30/2015 7:59:59 PM

Subject:
CN=Philipp B. Winterberg, O=Philipp B. Winterberg, STREET=Mecklenburger Str. 21, L=Münster, S=NRW, PostalCode=48147, C=DE

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0ca313e6b88e9f097241db43e8c7d876

Scanner detections:
Detections  (98% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.PhilippBWinterberg.Z, PUP.PhilippBWinterberg.R, PUP.PhilippBWinterberg.S, PUP.PhilippBWinterberg.Q, PUP.Installer.PhilippBWinterberg.X, PUP.Installer.PhilippBWinterberg.h, PUP.Installer.PhilippBWinterberg.S, PUP.PhilippBWinterberg.Installer (M), PUP.PhilippBWinterberg (M)
100.00%

Malwarebytes
PUP.Optional.OpenCandy
51.02%

Rising Antivirus
PE:PUF.OpenCandy!1.9DE5
48.98%

Trend Micro House Call
TROJ_GEN.F47V1210, Suspicious_GEN.F47V1201
40.82%

G Data
NSIS.Application.OpenCandy, Win32.Adware.OpenCandy, NSIS.Adware.SoftBundled
38.78%

ESET NOD32
Win32/OpenCandy, Win32/Bundled.Toolbar.Ask (variant), Win32/OpenCandy (variant)
32.65%

Dr.Web
Threat.Undefined, Adware.OpenCandy.7
30.61%

Agnitum Outpost
Riskware.OpenCandy
30.61%

Fortinet FortiGate
Riskware/OpenCandy
28.57%

ESET NOD32
Win32/OpenCandy potentially unsafe application
20.41%

1 / 68      (Adware)
rarzillafreeunrar.exe  (c0f1bdeb864cb5ce234be8287c84c9c8)

7 / 68      (Adware)

10 / 68    (Adware)

1 / 68      (Adware)
rarfileopenknife.exe  (f516b56633f85a7bda8fd3485b371159)

1 / 68      (Adware)
freerarextractfrog.exe  (ee7eccb46b8e6b33ce544bca1dd09826)

7 / 68      (Adware)

1 / 68      (Adware)
extractappsmuseum.exe  (750841e3f2ab0767d016983289f0626e)

1 / 68      (Adware)

1 / 68      (Adware)
rarzillafreeunrar.exe  (437a54a26881be19171b42e4bf5658b0)

7 / 68      (Adware)

0 / 68
freerarextractfrog.exe  (dae6a5222d7bf4bd66a40d86a964d6f5)

1 / 68      (Adware)
rarfileopenknife.exe  (402f38fbd014b944f8a3b8321d5fd815)

1 / 68      (Adware)
rarzillafreeunrar.exe  (2cc9dc1277f987d07a73cd2251e207a3)

1 / 68      (Adware)

7 / 68      (Adware)

1 / 68      (Adware)
rarfileopenknife.exe  (265fdbf5bd69b5f2a7a659466ee39b35)

1 / 68      (Adware)
rarzillafreeunrar.exe  (04514a4a20a67b71874bb3ce2fc2046c)

1 / 68      (Adware)
freerarextractfrog.exe  (7c817315eaf59b01c10357f167ae990e)

7 / 68      (Adware)

8 / 68      (Adware)

6 / 68      (Adware)

 
Latest 30 of 55 files

Downloads URLs for files signed by Philipp B. Winterberg.

7 / 68      (Adware)

10 / 68    (Adware)

10 / 68    (Adware)

10 / 68    (Adware)
http://www.philipp-winterberg.de/.../InstallRarZilla.exe  (fd5e6139747179aff22241d9b7424a22)

7 / 68      (Adware)
http://i.softplanet.com/.../Free-RAR-Extract-Frog650.exe  (674452b9076213b0adcfa4b2cd49de56)

1 / 68      (Adware)

10 / 68    (Adware)

10 / 68    (Adware)

1 / 68      (Adware)
http://dl.cdn.chip.de/downloads/.../Install55RarZilla.exe  (edfa6bd93c4c5587e5c6fea500cbe323)

10 / 68    (Adware)

7 / 68      (Adware)

1 / 68      (Adware)

10 / 68    (Adware)

10 / 68    (Adware)

10 / 68    (Adware)

10 / 68    (Adware)

10 / 68    (Adware)

7 / 68      (Adware)

7 / 68      (Adware)

7 / 68      (Adware)

10 / 68    (Adware)

10 / 68    (Adware)

7 / 68      (Adware)

10 / 68    (Adware)
http://www.philippwinterberg.com/.../InstallRarZilla.exe  (fd5e6139747179aff22241d9b7424a22)

 
Latest 30 of 76 download URLs

The following websites host and distribute files published by Philipp B. Winterberg.

The following publishers (by Authenticode signature organization name) are related.

30 of 74 publishers

Remove Philipp B. Winterberg Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to Philipp B. Winterberg by COMODO CA Limited on March 29, 2012 with the serial number '0ca313e6b88e9f097241db43e8c7d876'.