Sevas-S LLC

Publisher Information

Sevas-S LLC is a software developer located in Kyiv, Kyivska Oblast in Ukraine*. The company is a primary distributor of unwanted software. Thre are 2 additional code signing certificates issued to this publisher.
Remove Sevas-S LLC Malware - Powered by Reason Core Security
Authority:
VeriSign, Inc.

Valid from:
1/23/2013 7:00:00 AM

Valid to:
2/23/2014 6:59:59 AM

Subject:
CN=Sevas-S LLC, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Sevas-S LLC, L=Kyiv, S=Kyivska oblast, C=UA

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
527471e53862e2f90ab45ed4acb8f4c2

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.SevasS.Installer (M)
100.00%

McAfee
Artemis!DEF32AE932B4
2.00%

Malwarebytes
PUP.Optional.OpenCandy
2.00%

Dr.Web
Adware.Downware.1446
2.00%

VIPRE Antivirus
Sevas-S Installer
2.00%

McAfee Web Gateway
Artemis!DEF32AE932B4
2.00%

ESET NOD32
Win32/JoyDownloader
2.00%

Rising Antivirus
PE:PUF.OpenCandy!1.9DE5
2.00%

AVG
Downloader
2.00%

Bkav FE
W32.Clod928.Trojan
2.00%

1 / 68      (Adware)
ie10-windows6.1-x86-en-us-oc-jd.exe  (0cc2c9c35317822ebd1f6f1f131ad25b)

1 / 68      (Adware)
combofix-oc-jd.exe  (c2ea5a2826592af4f49a4c684d0a69e9)

1 / 68      (Adware)
opera_15.0.1147.141_setup-oc-jd.exe  (1801f0604aad96b13810ef8217f393fd)

1 / 68      (Adware)
ymsgr1150_0228_us-oc-jd.exe (Yahoomessenger)  (5344cf2d288187ece4189df957840cbd)

1 / 68      (Adware)
wordview_en-us-oc-jd.exe  (739771c2e0b47d77055ace6ab421aa2f)

1 / 68      (Adware)
ffsetup3.1.0-aoc-jd.exe (Format factory)  (fc7d087a8c3447bde1c6e045ed953cbe)

1 / 68      (Adware)
directx_jun2010_redist-oc-jd.exe (Directx)  (9d5394c94ac2607373c51ab47de0114b)

1 / 68      (Adware)
skypesetupfull-jd.exe (Skype)  (52cd3b893cda8fec1f9320e08cf5e6ba)

1 / 68      (Adware)
powerdvd_13.0.3105.58_dvd130327-04-aoc-jd.exe (Powerdvd)  (8ef81a6c91425402e89c14e702a0ba4f)

1 / 68      (Adware)
realplayer-fdu.exe  (6352b15ee3eff0854055f26be3b4f507)

1 / 68      (Adware)

25 / 68    (Adware)
windows-movie-maker-2.6.4037.0.exe (Windows Movie Maker)  (299be531ea4f6a074c80fae0d340a207)

1 / 68      (Adware)
dropbox2.4.3-aoc-jd.exe (Dropbox)  (982c7ad66eb0c6333322aa27a0074c65)

1 / 68      (Adware)
ie9-windows7-x64-enu-fdu.exe  (68723cfa2ea0153b6fa8f1baa6cd70ea)

1 / 68      (Adware)
setup_2.6.0-aoc-jd.exe (Nimbuzz)  (9284ba80d3e1ba56f100e76fa9d34c24)

1 / 68      (Adware)
wmp11-windowsxp-x86-enu-fdu.exe  (4d5e341b9e7a61b81a7f84ce4dfd8c4c)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
powerpoint-14.0.4754.1000.exe (PowerPoint Viewer)  (6099b2a91952b9f5736fc714d32e0c4b)

1 / 68      (Adware)
nero_burnlite-10.0.10600-fdu.exe  (5a5425ed4ca0aabbf933dac0f0bbcad7)

1 / 68      (Adware)
kiessetup-fdu.exe  (0a1d2ca47e5a3f145851f32cbf0e83bc)

1 / 68      (Adware)
mm26_enu-avg-jd.2013-09-24&c=14  (c730130e6e81325420f7b1f26f1ea528)

1 / 68      (Adware)
avast_free_antivirus_setup-fdu.exe  (af4f32334bee810e8d0dde95e26c169b)

1 / 68      (Adware)
gta-5-theme-for-opera-1.0.exe (GTA 5 theme for Opera)  (22c2a77809cf1bbe93b46cd2e353c897)

1 / 68      (Adware)

1 / 68      (Adware)
virtualbox-4.3.2.90405.exe (VirtualBox)  (dad3e6541bd1ae87eee52a7b57364cfd)

1 / 68      (Adware)
wavepad-audio-editor-5.55.exe (Wavepad Audio Editor)  (8dc94b9bab651a15ebdacd23348536d8)

1 / 68      (Adware)
musescore-1.3-aoc-jd.exe (Musescore)  (47df85ff471afdcddf909c7b87d23eb3)

1 / 68      (Adware)
iflysoft-flash-player-fdu.exe  (6eaf734ab3742e8e98eb8b477dc170e9)

1 / 68      (Adware)
adbepprocs4_alp-aoc-jd.exe (Adobe premiere pro)  (a3c58d897f50da5fb46d863f6002eb89)

 
Latest 30 of 1,135 files

Downloads URLs for files signed by Sevas-S LLC.

1 / 68      (Adware)

1 / 68      (Adware)
http://www.joydownload.com/d/.../Dropbox2.4.3-aoc-jd.exe  (982c7ad66eb0c6333322aa27a0074c65)

1 / 68      (Adware)

The certificates below are also signed by Sevas-S LLC.

4B35AC223F4DB03D3B4C5368983A4B53  (Feb 23, 2014 to Mar 26, 2015)

6B59CDE153F9D6B8052599E505477C19  (Jan 23, 2012 to Jan 23, 2013)

The following publishers (by Authenticode signature organization name) are related.

Remove Sevas-S LLC Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to Sevas-S LLC by VeriSign, Inc. on January 23, 2013 with the serial number '527471e53862e2f90ab45ed4acb8f4c2'.