Stas Kosmov

Publisher Information

Stas Kosmov is a brand of publishers/developers run by WebPick Internet Holdings Ltd. located in Ramat Ha'Chayal Tel Aviv, Israel. The company is a primary distributor of unwanted software. Stas Kosmov is a developer of WebPick Internet Holdings and publishes a number of adware web browser plugins designed to monitor web browser behavior and inject advertisements (banner, popups, text-links, etc.) in the browser by using the WebPick InstalleRex monetization delivery platform. These programs from Stas Kosmov are typiclaly installed on a variety of names and misspellings and are very difficult to remove. According to WebPick, they use developers to sign their adware in order to "throw off competitors".
Remove Stas Kosmov Malware - Powered by Reason Core Security
Authority:
COMODO CA Limited

Valid from:
9/24/2013 2:00:00 AM

Valid to:
9/25/2014 1:59:59 AM

Subject:
CN=Stas Kosmov, O=Stas Kosmov, STREET=Levitana 21, L=Kiev, S=Kiev, PostalCode=03083, C=UA

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
7a2834207c5588f506d3cf09661e12f2

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.WebPick.StasKosmov (M), PUP.WebPick.StasKosmov.Installer (M), Adware.WebPick.Installer (M)
100.00%

Dr.Web
Adware.Downware.1541, Trojan.WebPick.2627, Threat.Undefined
20.00%

avast!
Win32:InstalleRex-BX [PUP], Win32:InstalleRex-EJ [PUP]
20.00%

VIPRE Antivirus
Threat.4150696
20.00%

Kaspersky
Trojan.Win32.AntiFW
20.00%

McAfee
PUP-FHQ!D6BB6F2CE8EA, Program.PUP-FHQ, PUP-FHQ!3B92E4719053
20.00%

Sophos
PUA 'InstallRex'
20.00%

Quick Heal
Trojan.AntiFW.A5
20.00%

Malwarebytes
PUP.Optional.InstalleRex
20.00%

Zillya! Antivirus
Trojan.AntiFW.Win32.253, Trojan.AntiFW.Win32.267, Trojan.AntiFW.Win32.315
20.00%

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
igi 4 the mark.exe (Supersoftware App)  (c03507a5df3089b9ebfb74089eb559a2)

1 / 68      (Adware)
igi 3 the plan.exe (Supersoftware App)  (b0062776571ab1e838bb745bbe622829)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

41 / 68    (Adware)
00000000 (Supersoftware App)  (0a4d59293f6d090608d7d23da26415dc)

23 / 68    (Adware)
download.exe (BrilliantInstaller)  (be65af4125e1bea24c2c9dd267d3c9e6)

1 / 68      (Adware)

1 / 68      (Adware)
setup.exe (MountainApp)  (b38230461677661e9ee530b784578528)

1 / 68      (Adware)
{blocked}.exe (BrilliantInstaller)  (98aa6cafd70f846ae3e0b994b260a334)

38 / 68    (Adware)
download.exe (Supersoftware App)  (53d650706fb82491534d41ee383b4695)

1 / 68      (Adware)

1 / 68      (Adware)
hdd_mechanic_setup.exe.exe (TopApp soft)  (a057805b243cac101622958b162240b4)

1 / 68      (Adware)
รถของเล่น.exe (Supersoftware App)  (a46a4f83fe7b237f9d1d2abd5c7f0a46)

38 / 68    (Adware)
00000000 (BrilliantInstaller)  (adcc6145d592ea91fbaccfd194f78fbc)

1 / 68      (Adware)

38 / 68    (Adware)
00000000 (BrilliantInstaller)  (4b8ccb8ec19902f1f57fcb4ffdac53d1)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
rajapedang-tamat.rar.exe (Supersoftware App)  (bb4fa533922922da443794331cb9e1be)

1 / 68      (Adware)
pendekarwanitasanhoa.rar_2.exe (Supersoftware App)  (c0311200a16bfb97f3b93bd4ae619546)

1 / 68      (Adware)
pendekarwanitasanhoa.rar.exe (Supersoftware App)  (46c4b9c175d98b9dce7a1ecddf810176)

1 / 68      (Adware)
11suling_emasdannagasiluman.rar.exe (Supersoftware App)  (65264601e6bb2f8d8a98c2e5de50ea81)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
soal_sbmptn_saintek.pdf.exe (TopApp soft)  (5811b9d1b686a679235cc1028b5ad227)

1 / 68      (Adware)
descargar juego.exe (Supersoftware App)  (4aee9cfc53873ed5573690cafac7c2e0)

 
Latest 30 of 502 files

Downloads URLs for files signed by Stas Kosmov.

1 / 68      (Adware)
http://sharesuper.info/.../Descargar Juego.exe  (4aee9cfc53873ed5573690cafac7c2e0)

1 / 68      (Adware)
http://sharesuper.info/.../descarga sin captcha.exe  (d15e187ece4aea88333414aefb0e9c91)

1 / 68      (Adware)
http://sharesuper.info/.../Descargar Juego.exe  (6d011cc4a20f6f150af53b6e17aa8f8f)

1 / 68      (Adware)
http://sharesuper.info/.../descarga sin captcha.exe  (b779563f8bf6376166d77a4a7003ac55)

The following publishers (by Authenticode signature organization name) are related.

Remove Stas Kosmov Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to Stas Kosmov by COMODO CA Limited on September 24, 2013 with the serial number '7a2834207c5588f506d3cf09661e12f2'.