Ruslan Musin

Publisher Information

Ruslan Musin is a brand of publishers/developers run by WebPick Internet Holdings Ltd. located in Ramat Ha'Chayal Tel Aviv, Israel. The company is a primary distributor of unwanted software. Ruslan Musin is a developer of WebPick Internet Holdings and publishes a number of adware web browser plugins designed to monitor web browser behavior and inject advertisements (banner, popups, text-links, etc.) in the browser by using the WebPick InstalleRex monetization delivery platform. These programs from Ruslan Musin are typiclaly installed on a variety of names and misspellings and are very difficult to remove. According to WebPick, they use developers to sign their adware in order to "throw off competitors".
Authority:
COMODO CA Limited

Valid from:
9/12/2013 7:00:00 PM

Valid to:
9/13/2014 6:59:59 PM

Subject:
CN=Ruslan Musin, O=Ruslan Musin, STREET=Raketnaya 24, L=Kiev, S=Kiev, PostalCode=03028, C=UA

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
1ad41e574d496eab815cf0e1000d52c3

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
Adware.WebPick.Installer.U, Adware.WebPick.Installer.?, Adware.WebPick.Installer.c, Adware.WebPick.Installer.N, PUP.Installer.RuslanMusin.AA, Adware.WebPick.Installer.I, Adware.WebPick.Installer.h, Adware.WebPick.Installer.g, Adware.WebPick.Installer.X, Adware.WebPick.Installer.H, Adware.WebPick.Installer.Y, Adware.WebPick.Installer.n, PUP.Installer.RuslanMusin.I, Adware.WebPick.Installer.i, Threat.Installer.RuslanMusin, Adware.WebPick.Installer (M), PUP.WebPick.RuslanMusin.Installer (M)
100.00%

Dr.Web
Adware.Downware.2108, Adware.Downware.1166, Threat.Undefined
76.00%

Kaspersky
Trojan.Win32.AntiFW
74.00%

avast!
Win32:InstalleRex-BP [PUP], Win32:InstalleRex-BQ [PUP], Win32:InstalleRex-DT [PUP]
72.00%

Quick Heal
Trojan.AntiFW.A5
72.00%

McAfee
PUP-FHQ!D62485E630CF, PUP-FHQ!C724BF1423D1, PUP-FHQ!CCE2B8CCCEC0, PUP-FHQ!366352AB4FCD, PUP-FHQ!292844A6BC64, PUP-FHQ!64468C9E2875
72.00%

Malwarebytes
PUP.Optional.InstalleRex, PUP.Optional.Installex
72.00%

NANO AntiVirus
Riskware.Win32.InfoLeak.cvgqot, Riskware.Win32.Adware.crcapk
72.00%

Comodo Security
Application.Win32.InstalleRex.KG
72.00%

VIPRE Antivirus
Trojan.Win32.Generic, Installerex/WebPick, Threat.4150696
72.00%

39 / 68    (Adware)
download.exe (AllaboutApp)  (2600af44e07ba08cffc5b8276bf49cd2)

1 / 68      (Adware)
download-1.exe (AllaboutApp)  (88ad4793506002c5f87e8cdb59958815)

1 / 68      (Adware)
supercondriaque fr.exe (AllaboutApp)  (34b3a1daa763abc87eac554c272d217d)

39 / 68    (Adware)
00000000 (AllaboutApp)  (509addce5a8924e40c8540fc2fe8b758)

39 / 68    (Adware)
download.exe (AllaboutApp)  (a719b62c11c424a7d4cab2009915a443)

1 / 68      (Adware)
the golden age of grotesque.exe (AllaboutApp)  (15c394d720c60c75b5b92425a9aa1022)

1 / 68      (Adware)
the golden age of grotesque.exe (AllaboutApp)  (3452415730964543c4a29a0187f3454c)

1 / 68      (Adware)
marilyn manson - lunchbox.exe (AllaboutApp)  (0d9609d696d4c3a3abf5713f9ad82725)

1 / 68      (Adware)

1 / 68      (Adware)
download.exe (AllaboutApp)  (255d23cde1c31b87492b126eb7d7d222)

1 / 68      (Adware)
00000001 (AllaboutApp)  (7d639cbd1a7bd6eeca4a9dc7cba56c09)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
{4d87f0c1-6278-4409-955f-527fe2b38075} (AllaboutApp)  (a2bf6f9b824356fc2ed1274c61629b8d)

1 / 68      (Adware)
shahgoosh 18.mp4.exe (AllaboutApp)  (e0e9707891774b15537f118b0a41b1b9)

13 / 68    (Adware)
able2extract professional 8.0.42.0.exe (AllaboutApp)  (a03c82124308d99ba298b170183b6d4d)

39 / 68    (Adware)
safeweb.exe (AllaboutApp)  (e2e97a5355ccce48ed420afe3def5524)

37 / 68    (Adware)
{bc432254-f009-40ec-94cf-93e3a2a8f432} (AllaboutApp)  (c6d17a2a9521a95a063b5e3f6dcb1c2d)

40 / 68    (Adware)
00000000 (AllaboutApp)  (8c8614610ff0a2d2bafefc3cdd4f9783)

37 / 68    (Adware)
download.exe (AllaboutApp)  (2fbf8ad52668236abcf2b4890e786008)

39 / 68    (Adware)
00000000 (AllaboutApp)  (ede614673dde298e2f269e2223add8f5)

37 / 68    (Adware)
00000000 (AllaboutApp)  (1daf3137081c9c8b80beb2418d1d85d0)

36 / 68    (Adware)
00000000 (AllaboutApp)  (4cee5afc489dec4bbe2497b851965186)

36 / 68    (Adware)
00000001 (AllaboutApp)  (ff2a69a7297aca1fe90092ff3bc45e2f)

31 / 68    (Adware)
00000000 (AllaboutApp)  (a0cbf9b15aa5741dc80f8b620f45dc13)

12 / 68    (Adware)
file-00100.exe (AllaboutApp)  (002b7ba53260c3e033effc81e395edaf)

33 / 68    (Adware)
file-00068.exe (AllaboutApp)  (001ba795d5d51b14b0745a9d700e2408)

36 / 68    (Adware)

35 / 68    (Adware)
dslrbooth serial number.exe (AllaboutApp)  (bac96cd4e6f762e3464161b0823e770a)

38 / 68    (Adware)
00000000 (AllaboutApp)  (b025cf27cf9d600b3f75446b894c03c4)

 
Latest 30 of 53 files

Downloads URLs for files signed by Ruslan Musin.

1 / 68      (Adware)
http://sharesuper.info/.../supercondriaque fr.exe  (34b3a1daa763abc87eac554c272d217d)

29 / 68    (Adware)

34 / 68    (Adware)
http://sharesuper.info/.../Download.exe  (0567904a74d9b89c21b556306679cb3d)

1 / 68      (Adware)
http://lp.ezdownloadpro.info/.../The Conjuring.exe  (221c6d92c04680b5c3ae5ff40320ef82)

28 / 68    (Adware)
http://sharesuper.info/.../spy net v2 6 ara zip.exe  (d62485e630cf536fc7103137be59ad54)

The following websites host and distribute files published by Ruslan Musin.

The following publishers (by Authenticode signature organization name) are related.

* Note, the details and description above are based on the code signing digital signature issued to Ruslan Musin by COMODO CA Limited on September 12, 2013 with the serial number '1ad41e574d496eab815cf0e1000d52c3'.