Roman Malinenko

Publisher Information

Roman Malinenko is a brand of publishers/developers run by WebPick Internet Holdings Ltd. located in Ramat Ha'Chayal Tel Aviv, Israel. The company is a primary distributor of unwanted software. Roman Malinenko is a developer of WebPick Internet Holdings and publishes a number of adware web browser plugins designed to monitor web browser behavior and inject advertisements (banner, popups, text-links, etc.) in the browser by using the WebPick InstalleRex monetization delivery platform. These programs from Roman Malinenko are typiclaly installed on a variety of names and misspellings and are very difficult to remove. According to WebPick, they use developers to sign their adware in order to "throw off competitors".
Authority:
COMODO CA Limited

Valid from:
8/19/2013 7:00:00 AM

Valid to:
8/20/2014 6:59:59 AM

Subject:
CN=Roman Malinenko, O=Roman Malinenko, STREET=Esplanadna 17, L=Kyev, S=Kyev, PostalCode=01001, C=UA

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
47e3645cfb0c3cb8130567c3e5223c1d

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
Adware.WebPick.Installer (M), PUP.WebPick.RomanMalinenko.Installer (M)
100.00%

VIPRE Antivirus
Trojan.Win32.Generic, Installerex/WebPick
12.00%

avast!
Win32:InstalleRex-BI [PUP], Win32:InstalleRex-AP [PUP]
12.00%

Dr.Web
Adware.Downware.1719
12.00%

Kaspersky
Trojan.Win32.AntiFW
12.00%

McAfee
PUP-FHQ!477449BF5100, PUP-FHQ!BF49C4C1F9D1
12.00%

Malwarebytes
PUP.Optional.Installex
12.00%

K7 Gateway Antivirus
Trojan , Unwanted-Program
12.00%

NANO AntiVirus
Riskware.Win32.Downware.cukhmy, Riskware.Win32.Downware.ctorcv
12.00%

Agnitum Outpost
Trojan.AntiFW
12.00%

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

12 / 68    (Adware)
download.exe (Appit by GreatSoft)  (c9ea0bd23a301ab87dabab205d1f468a)

1 / 68      (Adware)
saad lamjarred.exe (Appit by GreatSoft)  (0aaf76d62accbc7ef5bbe74edfa7458c)

1 / 68      (Adware)

1 / 68      (Adware)
ofice 2013 português.exe (Appit by GreatSoft)  (3ac13b4d27ce1fa5d5cd7b68ff3cd5b5)

1 / 68      (Adware)
office 2013.exe (Appit by GreatSoft)  (ea72d3b2c8fc1f4353f2f7e091512c98)

1 / 68      (Adware)
office 2013.exe (Appit by GreatSoft)  (52624967e2eb3b1da6305844fc828674)

1 / 68      (Adware)
office 2013.exe (Appit by GreatSoft)  (76790042732578848e46161a9d36a455)

1 / 68      (Adware)

1 / 68      (Adware)
microsoft office 2007 português.exe (Appit by GreatSoft)  (868a268df7db5f325d9b1ebb71a1ffae)

1 / 68      (Adware)

1 / 68      (Adware)
bruno e marrone - vidro fumê.exe (QuickSet)  (af529decf328bfd80b84224015cfc658)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

39 / 68    (Adware)
00000000 (Appit by GreatSoft)  (4515f20f8f92a6afa1c1ed77a5bab84c)

1 / 68      (Adware)
europe tomorrow.mp3.exe (Appit by GreatSoft)  (374cebf21f842d73fd223d9cfb798909)

12 / 68    (Adware)
download.exe (Appit by GreatSoft)  (2769f34a5dc5fbeb67c8559859c41495)

1 / 68      (Adware)
download.exe (Appit by GreatSoft)  (50e23725e8ea021f18f3ac2bb2971b80)

1 / 68      (Adware)
video bokep20gratis anak sma.exe (Appit by GreatSoft)  (e27cce7be6b5b0716293ee8d218311e5)

1 / 68      (Adware)

1 / 68      (Adware)
holes - louis sachar.exe (Appit by Beware)  (60326ff215cd9ae0b7188b26226b0f02)

1 / 68      (Adware)
lora - puisor (download).mp3.exe (Appit by GreatSoft)  (cf26d67a05dc2edad3fb0ce8bebc148e)

1 / 68      (Adware)
lora - puisor (download).mp3.exe (Appit by GreatSoft)  (734c81583af7d70c0bbd337dc4f014cb)

1 / 68      (Adware)

1 / 68      (Adware)

 
Latest 30 of 287 files

Downloads URLs for files signed by Roman Malinenko.

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

The following publishers (by Authenticode signature organization name) are related.

* Note, the details and description above are based on the code signing digital signature issued to Roman Malinenko by COMODO CA Limited on August 19, 2013 with the serial number '47e3645cfb0c3cb8130567c3e5223c1d'.