Shlomy Golani

Publisher Information

Shlomy Golani is a brand of publishers/developers run by WebPick Internet Holdings Ltd. located in Ramat Ha'Chayal Tel Aviv, Israel. The company is a primary distributor of unwanted software. Shlomy Golani is a developer of WebPick Internet Holdings and publishes a number of adware web browser plugins designed to monitor web browser behavior and inject advertisements (banner, popups, text-links, etc.) in the browser by using the WebPick InstalleRex monetization delivery platform. These programs from Shlomy Golani are typiclaly installed on a variety of names and misspellings and are very difficult to remove. According to WebPick, they use developers to sign their adware in order to "throw off competitors". There is one additional code signing certificate issued to this publisher.
Remove Shlomy Golani Malware - Powered by Reason Core Security
Authority:
COMODO CA Limited

Valid from:
6/6/2012 8:00:00 PM

Valid to:
6/7/2013 7:59:59 PM

Subject:
CN=Shlomy Golani, O=Shlomy Golani, STREET=Wingate 56, L=Beer Sheva, S=Israel, PostalCode=84428, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
1e72b983ed68d3d614bcf3d7eea59787

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
Adware.WebPick.Installer (M), PUP.WebPick.ShlomyGolani.Installer (M), PUP.WebPick.Installer
100.00%

Dr.Web
Adware.Downware.448, Adware.Downware.980, Adware.Downware.906
72.00%

VIPRE Antivirus
Trojan.Win32.Generic, Installerex/WebPick, Threat.4150696, Threat.4753027
72.00%

avast!
Win32:InstalleRex-AW [PUP], Win32:InstalleRex-Y [PUP], Win32:InstalleRex-Q [PUP]
72.00%

Bkav FE
HW32.CDB, W32.FamVT.AntiFWK.Trojan
72.00%

K7 Gateway Antivirus
Adware , Trojan , Unwanted-Program
72.00%

Agnitum Outpost
PUA.InstalleRex, Riskware.InstallMate, Adware.Generic
72.00%

NANO AntiVirus
Riskware.Win32.Downware.ctkpjt, Riskware.Win32.Downware.cvbqyt, Riskware.Win32.Agent.crfikt, Riskware.Win32.Downware.cscofz
72.00%

Sophos
InstallRex, PUA 'InstallRex'
72.00%

Comodo Security
Application.Win32.Bundledz.C, Application.Win32.InstalleRex.KG
72.00%

35 / 68    (Adware)
vaudix.exe (Setup by Premium)  (7df48d5447ca3663fca8144b53de73b6)

35 / 68    (Adware)
vaudix.exe (Setup by Premium)  (d7557cc5b7d3ec46c17569c164ad0717)

1 / 68      (Adware)
vaudix.exe (Setup by Premium)  (afe3b39f8b9ab9a980e34cab928f30da)

1 / 68      (Adware)
vaudix.exe (Setup by Premium)  (41d370792c7e8ee35acc64ec8cf61d5b)

1 / 68      (Adware)
vaudix.exe (Setup by Premium)  (199414cb4d9d8bc588844d187fa2535a)

27 / 68    (Adware)
vaudix.exe (Setup by Premium)  (92ff60b150bcbed8eddd49aa8a5fd71b)

35 / 68    (Adware)
vaudix.exe (Setup by Premium)  (70eb6578443b874974e6744484bb4a42)

1 / 68      (Adware)
vaudix.exe (Setup by CloudSoft)  (b6f07dc4a22a472da58bf80544e575de)

1 / 68      (Adware)
codec-v.exe (Setup by Premium)  (f03584e03f4bff3341d1a869d858b521)

33 / 68    (Adware)
vaudix.exe (RightClick)  (6c7d9c32f9827ad9d1443eaffd6bd258)

1 / 68      (Adware)
codec-v.exe (Setup by Premium)  (886edf58d7c7c28f39401908e265db53)

41 / 68    (Adware)
vaudix.exe (SoftSafe)  (c70ade74354acd2df61b594dcb59ac1a)

1 / 68      (Adware)
codec-v.exe (Setup by Premium)  (acfebc39932c21dbd1cd9dc0e7d5f2ea)

35 / 68    (Adware)
vaudix.exe (Setup by Premium)  (f6888fcc19435bb2b65e76b42e526ba6)

33 / 68    (Adware)
vaudix.exe (RightClick)  (49e53e0fc7f6940c379be3cb0f1024a8)

35 / 68    (Adware)
vaudix.exe (Setup by Premium)  (305f5d592625097b4096cf38797e79e2)

41 / 68    (Adware)
vaudix.exe (SoftSafe)  (fc59300538b461c516797795698902f2)

41 / 68    (Adware)
vaudix.exe (SoftSafe)  (d1900c931f6af74d1add78edee19fe8b)

1 / 68      (Adware)
vaudix.exe (RightClick)  (69c51cd7bf7eed55f480221bff09fb61)

35 / 68    (Adware)
vaudix.exe (Setup by Premium)  (ef9a514dc620a1802879e647f5126da8)

41 / 68    (Adware)
vaudix.exe (SoftSafe)  (a82cbc2b130a3178030a447fd89da77c)

35 / 68    (Adware)
vaudix.exe (Setup by Premium)  (12d96dfe4a734c1fff1d308df3143d3c)

35 / 68    (Adware)
vaudix.exe (Setup by Premium)  (63da1a3479e8bf678d027bed55f1d448)

35 / 68    (Adware)
vaudix.exe (Setup by Premium)  (7a5c21060abd4ba964b97b0d01dc479f)

35 / 68    (Adware)
vaudix.exe (Setup by Premium)  (829af14928325f2c73131214100e09de)

41 / 68    (Adware)
vaudix.exe (SoftSafe)  (7e7188940b78cba8901bce6ad1594303)

35 / 68    (Adware)
vaudix.exe (Setup by Premium)  (acc29d6b33ed21e051968ec00dcd5014)

35 / 68    (Adware)
vaudix.exe (Setup by Premium)  (b000828b73dde8899078e47d6ce5a5e1)

35 / 68    (Adware)
vaudix.exe (Setup by Premium)  (316b537a112ceecd7f9288b503835a34)

1 / 68      (Adware)
vaudix.exe (ClickIT)  (3274c75e35ae27fe717a6daf00c9ae2d)

 
Latest 30 of 204 files

Downloads URLs for files signed by Shlomy Golani.

35 / 68    (Adware)

The following certificate is also signed by Shlomy Golani.

009FC86200EC0FF58D1C39395238030858  (Jan 17, 2013 to Jan 18, 2014)

The following publishers (by Authenticode signature organization name) are related.

Remove Shlomy Golani Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to Shlomy Golani by COMODO CA Limited on June 06, 2012 with the serial number '1e72b983ed68d3d614bcf3d7eea59787'.