Sergey Petrov

Publisher Information

Sergey Petrov is a brand of publishers/developers run by WebPick Internet Holdings Ltd. located in Ramat Ha'Chayal Tel Aviv, Israel. The company is a primary distributor of unwanted software. Sergey Petrov is a developer of WebPick Internet Holdings and publishes a number of adware web browser plugins designed to monitor web browser behavior and inject advertisements (banner, popups, text-links, etc.) in the browser by using the WebPick InstalleRex monetization delivery platform. These programs from Sergey Petrov are typiclaly installed on a variety of names and misspellings and are very difficult to remove. According to WebPick, they use developers to sign their adware in order to "throw off competitors".
Authority:
COMODO CA Limited

Valid from:
8/21/2013 7:00:00 AM

Valid to:
8/22/2014 6:59:59 AM

Subject:
CN=Sergey Petrov, O=Sergey Petrov, STREET=Gaydara 13, L=Kyev, S=Kyev, PostalCode=01033, C=UA

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0ad084e865d27cd546d21db6edf89d48

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
Adware.WebPick.Installer (M), PUP.WebPick.SergeyPetrov.Installer (M)
100.00%

Emsisoft Anti-Malware
Application.Generic.657777, Trojan.Generic.11002459, Trojan.Generic.11450565, Trojan.Generic.11420210, Trojan.Generic.11417269
10.00%

VIPRE Antivirus
Threat.4150696, Installerex/WebPick
10.00%

Dr.Web
Trojan.WebPick.29
10.00%

avast!
Win32:InstalleRex-BI [PUP], Win32:InstalleRex-CZ [PUP], Win32:InstalleRex-BM [PUP], Win32:Installer-AP [PUP]
10.00%

Bkav FE
W32.FamVT.AntiFWK.Trojan, HW32.CDB
10.00%

MicroWorld eScan
Trojan.Generic.11419242, Trojan.Generic.11002459, Trojan.Generic.11450565, Trojan.Generic.11420210, Gen:Variant.Kazy.324119
10.00%

nProtect
Trojan/W32.AntiFW.323784, Trojan/W32.AntiFW.322144, Trojan/W32.AntiFW.323864, Trojan/W32.AntiFW.323712, Trojan.Generic.11450677
10.00%

Quick Heal
Trojan.AntiFW.A5
10.00%

McAfee
Program.PUP-FHQ, PUP-FHQ!2DAFEC145420
10.00%

39 / 68    (Adware)
download.exe (MyApps)  (d48a219029464edca0f3167d61824177)

37 / 68    (Adware)
download.exe (AppReady Software)  (ea8f50295297d00530c1eb4a256a3e15)

1 / 68      (Adware)
romantica.zip.exe (HostIt)  (d5248a12a14597e71bca27f5d3014cb7)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

41 / 68    (Adware)
00000000 (ApPure)  (bc056f3f682ba82c6955e7fd2e9ab80d)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
TSULoader.exe (SafeApp by SafeSoft)  (7fe15368eed36ea37504d4b8a4ea019c)

1 / 68      (Adware)
one last dance 2003 720p bluray x264-ifpd.exe (HostIt)  (db88871d95867c6e90e57144267acfb9)

1 / 68      (Adware)
one last dance 2003 720p bluray x264-ifpd.exe (HostIt)  (8c26eb0dbc092e76994d8f236ee133c6)

38 / 68    (Adware)
download.exe (SafeApp by SafeSoft)  (ca9ce55ffe9bb91abffd8d38e221d148)

1 / 68      (Adware)
00000001 (GreenApp)  (ce95d8a58acf71fa7f6931623ea23e3e)

1 / 68      (Adware)
nero portable 15.0.25.0 multilingual.exe (SnowApp)  (71cea009695efc8810cd877e6be17f92)

1 / 68      (Adware)

1 / 68      (Adware)
ind0me618b10.rar.exe (Right Soft)  (3872c3845072e837e01a65cd23fe2336)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
eo4viopm.exe (Appit by GreatSoft)  (5ab109ea818a77ba600aaa2813c9660b)

1 / 68      (Adware)
spt21baruexcel.rar.exe (HostIt)  (0dcc7e8706da7ce7caf3295aa4f0d0a0)

1 / 68      (Adware)
opera mini 6.5 handler.exe (MiniApp)  (54ef6eecaa4ec2f4a6a5c9dff67c749e)

40 / 68    (Adware)
00000000 (Rightapp software)  (1b399bd06812cde53012b488c39a3f6d)

1 / 68      (Adware)
iso2god v1 2 2 and god2iso v1 0 2[xbox360].exe (MiniApp)  (ed37ebf68e48bc8b6ed5da658728e2b9)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
cold play - paradise.exe (SuperbApp)  (fe47029eed09c50398c8d9db8979827b)

1 / 68      (Adware)
bastille_-_pompeii.mp3.exe (SuperbApp)  (7365a96defedd68690158f71187a8a00)

 
Latest 30 of 5,436 files

Downloads URLs for files signed by Sergey Petrov.

1 / 68      (Adware)
http://lp.ezdownloadpro.info/.../Romantica.zip.exe  (d5248a12a14597e71bca27f5d3014cb7)

1 / 68      (Adware)

1 / 68      (Adware)
http://sharesuper.info/.../ind0me618b10.rar.exe  (3872c3845072e837e01a65cd23fe2336)

1 / 68      (Adware)

The following publishers (by Authenticode signature organization name) are related.

* Note, the details and description above are based on the code signing digital signature issued to Sergey Petrov by COMODO CA Limited on August 21, 2013 with the serial number '0ad084e865d27cd546d21db6edf89d48'.