Shlomo Dayan

Publisher Information

Shlomo Dayan is a brand of publishers/developers run by WebPick Internet Holdings Ltd. located in Ramat Ha'Chayal Tel Aviv, Israel. The company is a primary distributor of unwanted software. Shlomo Dayan is a developer of WebPick Internet Holdings and publishes a number of adware web browser plugins designed to monitor web browser behavior and inject advertisements (banner, popups, text-links, etc.) in the browser by using the WebPick InstalleRex monetization delivery platform. These programs from Shlomo Dayan are typiclaly installed on a variety of names and misspellings and are very difficult to remove. According to WebPick, they use developers to sign their adware in order to "throw off competitors".
Authority:
COMODO CA Limited

Valid from:
1/22/2013 1:00:00 AM

Valid to:
1/23/2014 12:59:59 AM

Subject:
CN=Shlomo Dayan, O=Shlomo Dayan, STREET=Smadar 45, L=Tel Aviv, S=center, PostalCode=67126, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
413c7d68add60589106bcf7dc596fbba

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
Adware.WebPick.Installer.N, PUP.Installer.WebPick, Adware.AdInjector.Installer.WebPick, Adware.WebPick.Installer (M)
100.00%

avast!
Win32:InstalleRex-W [PUP], Win32:InstalleRex-AH [PUP], Win32:InstallMonstr-DE [PUP], Win32:InstalleRex-Z [PUP], Win32:InstalleRex-AI [PUP]
87.80%

Kaspersky
not-a-virus:Downloader.Win32.AdLoad, not-a-virus:HEUR:Downloader.Win32.AdLoad, Trojan.Win32.AntiFW, not-a-virus:AdWare.Win32.Agent
87.80%

Dr.Web
Adware.Downware.1719, Adware.Downware.1442, Adware.Downware.1541, Trojan.WebPick.4, Adware.Downware.1166
87.80%

Malwarebytes
PUP.Optional.InstalleRex, PUP.Optional.Installrex, PUP.Optional.Installex
85.37%

NANO AntiVirus
Riskware.Win32.Downware.cscocg, Riskware.Win32.Downware.crfmjd, Riskware.Win32.Downware.crfmjh, Riskware.Win32.Downware.csjrwt
85.37%

Comodo Security
Application.Win32.InstalleRex.KG, Application.Win32.InstalleRex.LL, Application.Win32.Agent.W
85.37%

VIPRE Antivirus
Installerex/WebPick, Trojan.Win32.Generic, Threat.4150696, Threat.4753027
85.37%

McAfee
PUP-FHQ!04B65674EDF2, PUP-FDX!BB75F3C84A12, PUP-FDX!3EAA78B1B142, PUP-FHQ!EB13D2DD0FDC, PUP-FHQ!BD03CCBB8944, Program.PUP-FHQ
85.37%

Agnitum Outpost
PUA.Downloader, Adware.Generic, PUA.InstalleRex, PUA.Downware, Adware.Agent
85.37%

38 / 68    (Adware)
skypemoticons.exe (SummerSoft)  (aa18bca8c4c44e689bcde84341e0d664)

40 / 68    (Adware)
skypemoticons.exe (QuickSet)  (fdf654ba31705e39430e4ac71c953cee)

40 / 68    (Adware)
skypemoticons.exe (QuickSet)  (4d422e536f1e7ef8b3be20731ce666e7)

1 / 68      (Adware)
skypemoticons.exe (MinWare by House Of Soft)  (c144b2f63bdae4a09e1340238b8fba36)

38 / 68    (Adware)
skypemoticons.exe (SummerSoft)  (638226bbf8f260858843877ce0e04c5d)

40 / 68    (Adware)
skypemoticons.exe (QuickSet)  (9795708bad13b67817e3f942a22a017d)

38 / 68    (Adware)
skypemoticons.exe (SummerSoft)  (f85cc1f4e103396cc3297f6aabb5ffcb)

1 / 68      (Adware)
skypemoticons.exe (SummerSoft)  (4f8456caf9b25b215ea5b67da4a10348)

1 / 68      (Adware)
skypemoticons.exe (WinterSoft)  (55802414c1eba366c2597acb68fa10e4)

1 / 68      (Adware)
skypemoticons.exe (WinterSoft)  (f2dffd7dfb1c897d8ed4b96b1913c61a)

1 / 68      (Adware)
skypemoticons.exe (WinterSoft)  (80a2016ce4499a7f7d904274635d6251)

38 / 68    (Adware)
skypemoticons.exe (SummerSoft)  (281a5b003be19830e8bc23f5a15b2570)

38 / 68    (Adware)
skypemoticons.exe (SummerSoft)  (501247f5c8d86f96f52069089d8c8632)

13 / 68    (Adware)
skypemoticons.exe (StarApp)  (d78774a795a9e9e9a199bd698134d2b7)

42 / 68    (Adware)
skypemoticons.exe (QuickSet)  (a1bbf5b84be0781da00276b723875439)

41 / 68    (Adware)
skypemoticons.exe (QuickSet)  (ff1c0571423ffdc0b82ffc8ca8be0416)

41 / 68    (Adware)
skypemoticons.exe (QuickSet)  (a8175a6c2df410e1bb31419d7006bc11)

41 / 68    (Adware)
skypemoticons.exe (QuickSet)  (50d002fadb962f8acfea3547f02541b8)

41 / 68    (Adware)
skypemoticons.exe (QuickSet)  (b20c6004df5a64e02ffc1ed13b7e4cde)

36 / 68    (Adware)
{b8bc5cfd-b994-48a1-8ee2-6161c40be239} (QuickSet)  (74618a1b7d1f88ead67d9b26a1b48b09)

39 / 68    (Adware)
skypemoticons.exe (SummerSoft)  (d0e551a355a0d1259f34f9063807fef4)

33 / 68    (Adware)
skypemoticons.exe (MinWare by House Of Soft)  (877137cfce2c6f7f0375f9b09e72d460)

33 / 68    (Adware)
skypemoticons.exe (MinWare by House Of Soft)  (b98e4f569b63322a8a7a6d79e1a1e683)

32 / 68    (Adware)
skypemoticons.exe (SummerSoft)  (6ad2f46f3dcf9cd2003d9f1b84ea5f3b)

34 / 68    (Adware)
skypemoticons.exe (QuickSet)  (1266516367a750a5b932c9cda9b874c8)

6 / 68      (Adware)
skypemoticons.exe (WinterSoft)  (3c8581b4b13c3de0ce4f7340b9c4146e)

31 / 68    (Adware)
skypemoticons.exe (SummerSoft)  (fb0c5c34bc3cdfd001e05306a55e3c0b)

31 / 68    (Adware)
skypemoticons.exe (LightWare by SoftWarehouse)  (e21cc0789aba4884551c26296bf50069)

34 / 68    (Adware)
skypemoticons.exe (WinterSoft)  (cca8d41081539dd0ec3972370b5c2659)

32 / 68    (Adware)
skypemoticons.exe (QuickSet)  (07cae94fc58149c53e9298f2b47f01a6)

 
Latest 30 of 41 files

Downloads URLs for files signed by Shlomo Dayan.

38 / 68    (Adware)

38 / 68    (Adware)

39 / 68    (Adware)

6 / 68      (Adware)

25 / 68    (Adware)
http://storebox1.info/.../  (skypemoticons.exe)

25 / 68    (Adware)
http://storebox1.info/v1387  (skypemoticons.exe)

25 / 68    (Adware)

25 / 68    (Adware)

32 / 68    (Adware)

32 / 68    (Adware)

32 / 68    (Adware)

32 / 68    (Adware)

32 / 68    (Adware)

32 / 68    (Adware)

The following websites host and distribute files published by Shlomo Dayan.

The following publishers (by Authenticode signature organization name) are related.

* Note, the details and description above are based on the code signing digital signature issued to Shlomo Dayan by COMODO CA Limited on January 22, 2013 with the serial number '413c7d68add60589106bcf7dc596fbba'.