IT CONSULT

Publisher Information

IT CONSULT is a software publisher located in Zhytomyr, Zhytomyrska in Ukraine*. A majority of the programs developed by the company can be classified as adware or other potentially unwanted programs. Thre are 4 additional code signing certificates issued to this publisher.
Authority:
COMODO CA Limited

Valid from:
3/17/2016 1:00:00 AM

Valid to:
3/18/2017 12:59:59 AM

Subject:
CN=IT CONSULT, OU=IT, O=IT CONSULT, STREET=Gogol street 4 Suite 320, L=Zhytomyr, S=Zhytomyrska, PostalCode=10012, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
36b1fa2d187b0b723e5255b5d098cef1

Scanner detections:
Detections  (91% detected)

Scan engine
Details
Detections

ESET NOD32
Win32/Amonetize.MB potentially unwanted application, Win32/Amonetize.QR potentially unwanted application
67.65%

Reason Heuristics
PUP.Amonetize.ITCONSUL.Installer (M), PUP.Amonetize.ITCONSUL (M), PUP.Amonetize (M)
64.71%

McAfee
Trojan.Artemis!E72A358D9CA0
44.12%

Dr.Web
Detection.Undefined, Trojan.Amonetize.3133
32.35%

VIPRE Antivirus
Threat.4150696, Trojan.Win32.Generic
32.35%

Kaspersky
not-a-virus:HEUR:AdWare.Win32.Amonetize
26.47%

Malwarebytes
PUP.Optional.Amonetize
2.94%

K7 AntiVirus
Adware
2.94%

NANO AntiVirus
Trojan.Win32.Amonetize.dytxrl
2.94%

ESET NOD32
Win32/Amonetize.MB potentially unwanted
2.94%

1 / 68      (PUP)
un7vc3y6g.exe (Setup)  (97d804813648b07f9a03e36ec8308cca)

1 / 68      (PUP)

1 / 68      (PUP)
1p578ywky.exe (Setup)  (5d41311441d3049d85ec5b100d7da4ae)

5 / 68      (PUP)
8ydrb3b9i.exe (Setup)  (10787d78f7d2c5953c49d359de92dabd)

5 / 68      (PUP)
ferb4dsp9.exe (Setup)  (566cd7aa79b1c437c2f9ca13cf75e827)

3 / 68      (PUP)
bundle_flowsurfcb.exe (Setup)  (548436d63f0cb007c84b9f41a189d4aa)

1 / 68      (PUP)
ni67efkd7.exe (Setup)  (c59e11c9a0063a83dff11f7abeb9d5b2)

3 / 68      (inconclusive)
7994z88cd.exe (Setup)  (1c94c122ac5959ac98e2580eb989aa51)

3 / 68      (PUP)

1 / 68      (PUP)
i3x6zio_.exe (ChecleaFC Stadium by StamfordBrige)  (42bef73e5830cb4f0b19356eab31f6a2)

3 / 68      (PUP)

3 / 68      (PUP)

4 / 68      (PUP)
9p7da7e5v.exe (Setup)  (c3799b513f3deadc2b8a2c9edcce5778)

3 / 68      (inconclusive)
gwrwxd777.exe (Setup)  (842d758f5c268e3594983260ce9bb9cd)

3 / 68      (PUP)

3 / 68      (PUP)

3 / 68      (inconclusive)
ux2gy9bkw.exe (Setup)  (a82422511bff11827841bc2d177b01f2)

3 / 68      (PUP)
setup__2140_il67.exe (ChecleaFC Stadium by StamfordBrige)  (e4f66ce39ccf0daf6e8b526166c3d1b7)

4 / 68      (PUP)
iopayynmv.exe (Setup)  (1a54991c49d854e0ac6927d3676faa86)

3 / 68      (PUP)
bundle_flowsurfcb.exe (Setup)  (97aa732909419fbb4bf88852c204e5b8)

4 / 68      (PUP)
a9avd80ni.exe (Setup)  (31b3741fa2eaaf2412a8568aaa8982de)

4 / 68      (PUP)
8vvmghd0p.exe (Setup)  (f0705be837efacea2d228056b58862c4)

3 / 68      (PUP)
9jz8ezz9h.exe (Setup)  (ce0eb6255f68e692683d52403415a9ff)

3 / 68      (PUP)
a24kkpmbf.exe (Setup)  (3982ddbc764bc95bd8c4e737c5295c3f)

14 / 68    (PUP)
xmul6wd6w.exe (Setup)  (13cae32ab51f8a65e2e9b7d2a4d11e00)

 
Latest 30 of 34 files

Downloads URLs for files signed by IT CONSULT.

3 / 68      (PUP)
http://www.power-ful.xyz/.../Bundle_FlowsurfCB.exe  (299d1781baadfa048d5b01e2dd772419)

The following websites host and distribute files published by IT CONSULT.

The certificates below are also signed by IT CONSULT.

61F7EF0A7B558B6BEB54449ABFC0146E  (Jun 11, 2015 to Jul 11, 2016)

327DDFADCCCFD04814683306224CE3CB  (Apr 15, 2014 to Jun 15, 2015)

422F6F2E59982040A0DBC4D7900DF99A  (Mar 26, 2013 to Apr 26, 2014)

771EBF22015D2DF1CE238CEF6357C1A8  (Apr 03, 2012 to Apr 03, 2013)

The following publishers (by Authenticode signature organization name) are related.

* Note, the details and description above are based on the code signing digital signature issued to IT CONSULT by COMODO CA Limited on March 17, 2016 with the serial number '36b1fa2d187b0b723e5255b5d098cef1'.