Sevas-S LLC

Publisher Information

Sevas-S LLC is a software developer located in Kyiv, Kyivska Oblast in Ukraine*. The company is a primary distributor of unwanted software. Thre are 2 additional code signing certificates issued to this publisher.
Remove Sevas-S LLC Malware - Powered by Reason Core Security
Authority:
VeriSign, Inc.

Valid from:
1/22/2012 7:00:00 PM

Valid to:
1/22/2013 6:59:59 PM

Subject:
CN=Sevas-S LLC, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Sevas-S LLC, L=Kyiv, S=Kyivska oblast, C=UA

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6b59cde153f9d6b8052599e505477c19

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.BHO.SevasS.AA, PUP.BHO.SevasS.L, PUP.SevasS.P, PUP.Task.SevasS.I, PUP.Task.SevasS.H, PUP.Installer.SevasS.Z, PUP.SevasS.AA, PUP.SevasS.R, PUP.SevasS.I, PUP.Installer.SevasS.N, PUP.SevasS.W, PUP.SevasS.X, PUP.Startup.SevasS.H, PUP.Installer.SevasS.V, PUP.SevasS.H, PUP.Installer.SevasS.O, PUP.Installer.SevasS.P, Threat.SevasS, PUP.SevasS (M), PUP.SevasS.Installer (M)
100.00%

VIPRE Antivirus
Threat.4847482, Sevas-S Installer
34.00%

Bkav FE
W32.Clodd3a.Trojan, W32.HfsAdware
16.00%

ESET NOD32
Win32/OpenCandy
12.00%

Malwarebytes
PUP.Optional.OpenCandy
10.00%

Rising Antivirus
PE:PUF.OpenCandy!1.9DE5
10.00%

Dr.Web
Adware.Downware.1446, Adware.Downware.11181
8.00%

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
8.00%

Agnitum Outpost
Packed/PECompact
6.00%

herdProtect (fuzzy)
a variant of 0cfce5206de8b7f4ea5676eb0a572f25654b865c, a variant of 4a454f6d84370f91d9553e5a563bf9accd676329
6.00%

3 / 68      (Adware)
updater.exe (Sevas-S Software Updater by Sevas-S)  (40fbf781d7db49ff37247facaaafba17)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
ffsetup300-d2c.exe  (4d9f3c5bf9b19542865eaf26b64ecb1f)

1 / 68      (Adware)
utorrent-3.3.exe  (897eb7b9a92f5b04c6bc2bf23c556368)

1 / 68      (Adware)
videodownloader.exe (Video Downloader by Sevas-S)  (fe59fcd272b398231902a8a06d1e26f3)

1 / 68      (Adware)
vlc-2.0.5-win32-d2c.exe  (aa301d2893a5d8c25cd13fd2974c1af5)

1 / 68      (Adware)
smtb_updater.exe (My Smart Tabs Updater by Sevas-S)  (2bb83a5cbd8ff44530553ea6186fe9d6)

3 / 68      (Adware)
yt2mp3converter.exe (YouTube to MP3 Converter by Sevas-S)  (4e1126e19400e28ac4dff9f9b50eda07)

1 / 68      (Adware)

1 / 68      (Adware)
MySmartTabs.dll (My Smart Tabs Extension by SEVAS-S)  (3b452cceb2e74c7ae86f1bd58c50b2e8)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
aresregular219_installer.exe  (ba2eb832c5116f633daf156c6fa3c268)

5 / 68      (Adware)

1 / 68      (Adware)
jre-7u11-windows-i586-d2c.exe  (6c0dd768d025275b9e799be08780eb8b)

2 / 68      (Adware)

1 / 68      (Adware)

2 / 68      (Adware)

11 / 68    (Adware)
ccsetup326.exe  (10080ba7e6166e91b3b8821ab1dbd783)

2 / 68      (Adware)

1 / 68      (Adware)
smtb_upd.exe (My Smart Tabs by Sevas-S)  (6ecd8e8b7425ab7bc0c93c5baa09e2c0)

1 / 68      (Adware)
MySmartTabs.dll (My Smart Tabs Extension by SEVAS-S)  (bb0a020199a2dbc7850d583b25d25d8e)

3 / 68      (Adware)
updater.exe (Sevas-S Software Updater by Sevas-S)  (592f3686c0b78263224425995d8fd556)

8 / 68      (Adware)

1 / 68      (Adware)
yt2mp3converter.exe (YouTube to MP3 Converter by Sevas-S)  (d961c17cf0319d5f6868185a39dfcd6f)

3 / 68      (Adware)
yt2mp3converter.exe (YouTube to MP3 Converter by Sevas-S)  (33e10a13236b981ea9149c108382140b)

3 / 68      (Adware)
updater.exe (Sevas-S Software Updater by Sevas-S)  (130a1a694ed7e2cc4b99b00007cefb52)

3 / 68      (Adware)

1 / 68      (Adware)
videodownloader.exe (Video Downloader by Sevas-S)  (5b2a278b73d826954939bdb1ba001030)

 
Latest 30 of 53 files

Downloads URLs for files signed by Sevas-S LLC.

8 / 68      (Adware)

The following websites host and distribute files published by Sevas-S LLC.

The certificates below are also signed by Sevas-S LLC.

4B35AC223F4DB03D3B4C5368983A4B53  (Feb 23, 2014 to Mar 26, 2015)

527471E53862E2F90AB45ED4ACB8F4C2  (Jan 23, 2013 to Feb 23, 2014)

The following publishers (by Authenticode signature organization name) are related.

Remove Sevas-S LLC Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to Sevas-S LLC by VeriSign, Inc. on January 22, 2012 with the serial number '6b59cde153f9d6b8052599e505477c19'.