SAfe downlOAd gtL

Publisher Information

SAfe downlOAd gtL is a software developer located in Dublin, Ireland*. The company is a primary distributor of unwanted software. Thre are 18 additional code signing certificates issued to this publisher.
Authority:
thawte, Inc.

Valid from:
6/4/2015 2:00:00 AM

Valid to:
1/28/2016 5:29:59 AM

Subject:
CN=SAfe downlOAd gtL, O=SAfe downlOAd gtL, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
02724984fe4b2a74debcd4865380b7ed

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Outbrowse (M), PUP.Outbrowse.Bundler
100.00%

1 / 68      (Adware)
setup.exe (GLUWH)  (ada3d3be511f6f1809b527f3e0e994d9)

1 / 68      (Adware)
setup.exe (BCRQS)  (2671515bd0768c6726da7b94a3031c6a)

1 / 68      (Adware)
easyyoutbedownloader.exe (XKHEV)  (26cee8497933f00634c2219d0766f1ad)

1 / 68      (Adware)
virtualvillagers.exe (NHFFH)  (9d183496fc3f3767fbd1592227171912)

1 / 68      (Adware)
virtualfamilies.exe (QDGJO)  (32abdfa9571a353edc4df20df130b45e)

1 / 68      (Adware)
turbosub.exe (MZWWL)  (93e23f9020cf8cdefbbbe52611cff65a)

1 / 68      (Adware)
turbopizza.exe (WZRLG)  (55bbe274ba3ec53ee045974aeed66c2c)

1 / 68      (Adware)
montezuma3.exe (BBLTJ)  (6e18c7be4eb7a1bacbcfccb133e75a7e)

1 / 68      (Adware)
sherlockholmes2.exe (VMATT)  (61fe0fd3ccb38dd29997572e70ea239e)

1 / 68      (Adware)
slingoquest.exe (MVAKX)  (e51ccde5aa7e62ea72f98d89e33bd844)

1 / 68      (Adware)
poppit.exe (IWTDU)  (af7fe17f2bae04b5df6d7af3c7ea23c5)

1 / 68      (Adware)
setup.exe (UZOJW)  (9979a9c3f1dc72e21060e887b8bdebd2)

1 / 68      (Adware)
setup.exe (QJDTA)  (30bfe9269540ed331783eb63d9418273)

1 / 68      (Adware)
كلاش (JCPQV)  (72fd2e110d6fbe153f140be1edfd07a1)

1 / 68      (Adware)
setup.exe (XWVDQ)  (df8bb4c4abe88f6669005d2665ea5d7a)

1 / 68      (Adware)
setup.exe (GSZHQ)  (afdc22a0b9df5d1d7a91beea623d2de1)

1 / 68      (Adware)
setup.exe (LFGXL)  (5e33d361a1004e16704a80cfd8f7e022)

1 / 68      (Adware)
setup.exe (YRQMO)  (45949f487ee617b9081309e1be88c77a)

1 / 68      (Adware)

1 / 68      (Adware)
euuk0mob.exe (VGOOU)  (9c8adb13f664eb38a181339e1104577b)

1 / 68      (Adware)
setup.exe (IVGER)  (aa3df80cc2f5c8dd42d05f7ef47f6662)

1 / 68      (Adware)
{blocked}.exe (LPYIY)  (ad7f0f16cf1d13a983702c1319971174)

1 / 68      (Adware)
setup.exe (EIIAR)  (cbf851a1b703cf7cc74c7498c2042c56)

1 / 68      (Adware)
setup.exe (LNYMT)  (35ce2bba3bc98d863e6800c98cc6055a)

1 / 68      (Adware)
adobe_flash_player.exe (GSSDB)  (c6c9e2c99fdc8450508492734fb62ff1)

1 / 68      (Adware)
setup installer.exe (BJHNF)  (7e0ec20bf15fb7e79282a7f11d7f3d8c)

1 / 68      (Adware)
setup.exe (SCINW)  (3e74a1baebd6505791b0449acf6ba85f)

1 / 68      (Adware)
setup.exe (LVTJX)  (838af8800742afb44dc4ecc9b4752973)

1 / 68      (Adware)
autodesk.inventor.pro.2015.x64.exe (DBMBD)  (a953a245e37e3787cd54574d7bfc7420)

1 / 68      (Adware)
setup.exe (JACRS)  (61547de95fd3d166d5912c00f7a27b9b)

 
Latest 30 of 2,561 files

The certificates below are also signed by SAfe downlOAd gtL.

69CC55B6077EC8DA48D66E1527EEB161  (Apr 08, 2015 to Jan 28, 2016)

14A25C18D3A961BACA6D7C2A3D718B0A  (Jan 27, 2015 to Jan 28, 2016)

192FD0582FF4A089E022A8269E29823B  (Apr 30, 2015 to Jan 28, 2016)

4D753B2AA88378503DFD6C737E4D9BB1  (Nov 10, 2015 to Jan 28, 2016)

52C30E423F995D6F84A108D53F985864  (May 28, 2015 to Jan 28, 2016)

561EB78CC36593FFA0AB34CB8F670F07  (Mar 01, 2015 to Jan 28, 2016)

263ED9CA1E1EB9DDF77844540EB8042F  (Apr 12, 2015 to Jan 27, 2016)

2F97ABCC05BC3B564497EC9E69ECC926  (Feb 26, 2015 to Jan 27, 2016)

40E518817F8504A5C7C7E38B8840856D  (Apr 21, 2015 to Jan 27, 2016)

04DC360F2C51DF27FBB32CA79D999219  (May 03, 2015 to Jan 27, 2016)

10 of 18 code signing certificates issued

The following publishers (by Authenticode signature organization name) are related.

* Note, the details and description above are based on the code signing digital signature issued to SAfe downlOAd gtL by thawte, Inc. on June 04, 2015 with the serial number '02724984fe4b2a74debcd4865380b7ed'.