Stas Kosmov

Publisher Information

Stas Kosmov is a brand of publishers/developers run by WebPick Internet Holdings Ltd. located in Ramat Ha'Chayal Tel Aviv, Israel. The company is a primary distributor of unwanted software. Stas Kosmov is a developer of WebPick Internet Holdings and publishes a number of adware web browser plugins designed to monitor web browser behavior and inject advertisements (banner, popups, text-links, etc.) in the browser by using the WebPick InstalleRex monetization delivery platform. These programs from Stas Kosmov are typiclaly installed on a variety of names and misspellings and are very difficult to remove. According to WebPick, they use developers to sign their adware in order to "throw off competitors".
Authority:
COMODO CA Limited

Valid from:
9/24/2013 2:00:00 AM

Valid to:
9/25/2014 1:59:59 AM

Subject:
CN=Stas Kosmov, O=Stas Kosmov, STREET=Levitana 21, L=Kiev, S=Kiev, PostalCode=03083, C=UA

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
7a2834207c5588f506d3cf09661e12f2

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.WebPick.StasKosmov (M), PUP.WebPick.StasKosmov.Installer (M), Adware.WebPick.Installer (M)
100.00%

Dr.Web
Adware.Downware.1541, Trojan.WebPick.2627, Threat.Undefined
20.00%

avast!
Win32:InstalleRex-BX [PUP], Win32:InstalleRex-EJ [PUP]
20.00%

VIPRE Antivirus
Threat.4150696
20.00%

Kaspersky
Trojan.Win32.AntiFW
20.00%

McAfee
PUP-FHQ!D6BB6F2CE8EA, Program.PUP-FHQ, PUP-FHQ!3B92E4719053
20.00%

Sophos
PUA 'InstallRex'
20.00%

Quick Heal
Trojan.AntiFW.A5
20.00%

Malwarebytes
PUP.Optional.InstalleRex
20.00%

Zillya! Antivirus
Trojan.AntiFW.Win32.253, Trojan.AntiFW.Win32.267, Trojan.AntiFW.Win32.315
20.00%

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
igi 4 the mark.exe (Supersoftware App)  (c03507a5df3089b9ebfb74089eb559a2)

1 / 68      (Adware)
igi 3 the plan.exe (Supersoftware App)  (b0062776571ab1e838bb745bbe622829)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

41 / 68    (Adware)
00000000 (Supersoftware App)  (0a4d59293f6d090608d7d23da26415dc)

23 / 68    (Adware)
download.exe (BrilliantInstaller)  (be65af4125e1bea24c2c9dd267d3c9e6)

1 / 68      (Adware)

1 / 68      (Adware)
setup.exe (MountainApp)  (b38230461677661e9ee530b784578528)

1 / 68      (Adware)
{blocked}.exe (BrilliantInstaller)  (98aa6cafd70f846ae3e0b994b260a334)

38 / 68    (Adware)
download.exe (Supersoftware App)  (53d650706fb82491534d41ee383b4695)

1 / 68      (Adware)

1 / 68      (Adware)
hdd_mechanic_setup.exe.exe (TopApp soft)  (a057805b243cac101622958b162240b4)

1 / 68      (Adware)
รถของเล่น.exe (Supersoftware App)  (a46a4f83fe7b237f9d1d2abd5c7f0a46)

38 / 68    (Adware)
00000000 (BrilliantInstaller)  (adcc6145d592ea91fbaccfd194f78fbc)

1 / 68      (Adware)

38 / 68    (Adware)
00000000 (BrilliantInstaller)  (4b8ccb8ec19902f1f57fcb4ffdac53d1)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
rajapedang-tamat.rar.exe (Supersoftware App)  (bb4fa533922922da443794331cb9e1be)

1 / 68      (Adware)
pendekarwanitasanhoa.rar_2.exe (Supersoftware App)  (c0311200a16bfb97f3b93bd4ae619546)

1 / 68      (Adware)
pendekarwanitasanhoa.rar.exe (Supersoftware App)  (46c4b9c175d98b9dce7a1ecddf810176)

1 / 68      (Adware)
11suling_emasdannagasiluman.rar.exe (Supersoftware App)  (65264601e6bb2f8d8a98c2e5de50ea81)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
soal_sbmptn_saintek.pdf.exe (TopApp soft)  (5811b9d1b686a679235cc1028b5ad227)

1 / 68      (Adware)
descargar juego.exe (Supersoftware App)  (4aee9cfc53873ed5573690cafac7c2e0)

 
Latest 30 of 502 files

Downloads URLs for files signed by Stas Kosmov.

1 / 68      (Adware)
http://sharesuper.info/.../Descargar Juego.exe  (4aee9cfc53873ed5573690cafac7c2e0)

1 / 68      (Adware)
http://sharesuper.info/.../descarga sin captcha.exe  (d15e187ece4aea88333414aefb0e9c91)

1 / 68      (Adware)
http://sharesuper.info/.../Descargar Juego.exe  (6d011cc4a20f6f150af53b6e17aa8f8f)

1 / 68      (Adware)
http://sharesuper.info/.../descarga sin captcha.exe  (b779563f8bf6376166d77a4a7003ac55)

The following publishers (by Authenticode signature organization name) are related.

* Note, the details and description above are based on the code signing digital signature issued to Stas Kosmov by COMODO CA Limited on September 24, 2013 with the serial number '7a2834207c5588f506d3cf09661e12f2'.