YL production

Publisher Information

YL production is a brand of publishers/developers run by WebPick Internet Holdings Ltd. located in Ramat Ha'Chayal Tel Aviv, Israel. This developer was issued an Open Source Code Signing certificate. The publisher is a primary distributor of unwanted software. YL production is a developer of WebPick Internet Holdings and publishes a number of adware web browser plugins designed to monitor web browser behavior and inject advertisements (banner, popups, text-links, etc.) in the browser by using the WebPick InstalleRex monetization delivery platform. These programs from YL production are typiclaly installed on a variety of names and misspellings and are very difficult to remove. According to WebPick, they use developers to sign their adware in order to "throw off competitors".
Authority:
Unizeto Technologies S.A.

Valid from:
1/16/2014 1:49:26 PM

Valid to:
1/16/2015 1:49:26 PM

Subject:
E=Lebedev72@hotmail.com, CN="Open Source Developer, Yuri LEBEDEV", O=YL production, C=RU

Issuer:
CN=Certum Level III CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
284b7b8274afc7e851a73b98b619311f

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
Adware.WebPick.Installer (M), PUP.WebPick.YLproduction.Installer (M)
100.00%

VIPRE Antivirus
Threat.4150696, Trojan.Win32.Generic
18.00%

avast!
Win32:InstalleRex-BW [PUP]
18.00%

Dr.Web
Trojan.WebPick.2579, Adware.Downware.2108
18.00%

Bkav FE
HW32.CDB, W32.FamVT.AntiFWK.Trojan
18.00%

MicroWorld eScan
Trojan.Generic.11372550, Trojan.Generic.11349117, Application.Generic.650782, Trojan.Generic.11359083
18.00%

nProtect
Trojan/W32.AntiFW.322592, Trojan/W32.AntiFW.322576, Trojan.Generic.11359083
18.00%

Quick Heal
Trojan.AntiFW.A5
18.00%

McAfee
PUP-FHQ, Program.PUP-FHQ, PUP-FHQ!21AEF4262056
18.00%

Malwarebytes
PUP.Optional.InstalleRex
18.00%

1 / 68      (Adware)
mr.probz.exe (BrilliantInstaller)  (8a76f5db82900f3e4e1a21bcf872c116)

1 / 68      (Adware)
mr.probz.exe (BrilliantInstaller)  (e7d6c86136b51b69b6b83c71554307fc)

39 / 68    (Adware)
download.exe (TopApp soft)  (79434aa37804efcbd04264f4cb7c671d)

1 / 68      (Adware)
mac-p1.rar.exe (TopApp soft)  (f1a53b38ea80b1ed440864c94c5397ff)

1 / 68      (Adware)
mac-p1.rar.exe (TopApp soft)  (fe4e5849385297c0d6548d9313ae6fe0)

1 / 68      (Adware)
winhiip_v1.7.6.rar.exe (BrilliantInstaller)  (926ac8fbc7d7877fd0fcff8f56fbfbdd)

1 / 68      (Adware)
winhiip_v1.7.6.rar.exe (BrilliantInstaller)  (715a8d5d45973de05bfd72503843340f)

1 / 68      (Adware)
shakira dare la la la song mp3 download.exe (TopApp soft)  (d9714488d0273d5dfad63472e961ed0b)

1 / 68      (Adware)
00000000 (Application fields Software)  (678285caa5d70ff74f1991bfa6a305b2)

1 / 68      (Adware)
pelislatino3gp.net.disaste.movie.3gp.exe (TopApp soft)  (ed9d282e495f4a74a9514a56d3f586c9)

39 / 68    (Adware)
download.exe (TopApp soft)  (e2e3b706f5c2734d899bfab768d62325)

1 / 68      (Adware)
song.mp3.exe (TopApp soft)  (8e6b9c5dbfae630e42c38a6b9520999c)

1 / 68      (Adware)
v2972.exe (TopApp soft)  (df5e9259068d1e87b5996ed508afd5f3)

1 / 68      (Adware)

38 / 68    (Adware)
00000000 (TopApp soft)  (83c8cf5f15dbd34240516172cf07643e)

1 / 68      (Adware)
secawan madu koplo.exe (BrilliantInstaller)  (7eae5559e08e1eb20541a6edcc7dd81a)

1 / 68      (Adware)
xxx pakistani.exe (BrilliantInstaller)  (699263ad739060f5d371251f523be797)

1 / 68      (Adware)
xxx pakistani.exe (BrilliantInstaller)  (f024c7236e04eb18ba32cf0c8f681925)

1 / 68      (Adware)
xxx pakistani.exe (BrilliantInstaller)  (8914b62b0a8074c4390520b4a05927b4)

39 / 68    (Adware)
download.exe (TopApp soft)  (f0a0e258428e677650c0ab2e00d020a1)

39 / 68    (Adware)
00000000 (BrilliantInstaller)  (c117a23b2743519ae5ead556749b3ca6)

1 / 68      (Adware)
runner runner.exe (TopApp soft)  (3c50929610a13f4066b9f2d73372d4d4)

1 / 68      (Adware)
delivery man.exe (TopApp soft)  (6db76ab6e73e191359801cd7b370f7df)

1 / 68      (Adware)
of mice.exe (TopApp soft)  (7a1bb01946677c04f1ec400627df7467)

1 / 68      (Adware)

1 / 68      (Adware)
m.tulkit2.5.0.rar.exe (BrilliantInstaller)  (26f1dca13f7ad89967ae2bb542a6a7c6)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

 
Latest 30 of 322 files

Downloads URLs for files signed by YL production.

1 / 68      (Adware)
http://sharesuper.info/.../Mr.Probz.exe  (e7d6c86136b51b69b6b83c71554307fc)

1 / 68      (Adware)
http://sharesuper.info/.../MAC-P1.rar.exe  (fe4e5849385297c0d6548d9313ae6fe0)

1 / 68      (Adware)

1 / 68      (Adware)

The following publishers (by Authenticode signature organization name) are related.

* Note, the details and description above are based on the code signing digital signature issued to YL production by Unizeto Technologies S.A. on January 16, 2014 with the serial number '284b7b8274afc7e851a73b98b619311f'.