{"id":1136,"date":"2014-07-25T18:52:41","date_gmt":"2014-07-25T18:52:41","guid":{"rendered":"http:\/\/www.freefixer.com\/b\/?p=1136"},"modified":"2018-05-29T12:02:50","modified_gmt":"2018-05-29T12:02:50","slug":"information-technology-systems-doo","status":"publish","type":"post","link":"https:\/\/www.freefixer.com\/b\/information-technology-systems-doo\/","title":{"rendered":"Information Technology Systems doo &#8211; VirusTotal Report"},"content":{"rendered":"<p>Just wanted to give you the heads up on a publisher called\u00a0<strong>Information Technology Systems doo.<\/strong><\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/07\/Information-Technology-Systems-doo-Publisher.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-1139\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/07\/Information-Technology-Systems-doo-Publisher.png\" alt=\"Information Technology Systems doo Publisher\" width=\"472\" height=\"268\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/07\/Information-Technology-Systems-doo-Publisher.png 472w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/07\/Information-Technology-Systems-doo-Publisher-300x170.png 300w\" sizes=\"(max-width: 472px) 100vw, 472px\" \/><\/a><\/p>\n<p>According to the certificate, the publisher is located in Montenegro:<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/07\/Information-Technology-Systems-doo-Certificate.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-1138\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/07\/Information-Technology-Systems-doo-Certificate.png\" alt=\"Information Technology Systems doo Certificate\" width=\"591\" height=\"573\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/07\/Information-Technology-Systems-doo-Certificate.png 591w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/07\/Information-Technology-Systems-doo-Certificate-300x290.png 300w\" sizes=\"(max-width: 591px) 100vw, 591px\" \/><\/a><\/p>\n<p>This is the VirusTotal scan report for the\u00a0Information Technology Systems doo file:<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/07\/Information-Technology-Systems-doo-VirusTotal.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-1137\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/07\/Information-Technology-Systems-doo-VirusTotal.png\" alt=\"Information Technology Systems doo - VirusTotal\" width=\"719\" height=\"406\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/07\/Information-Technology-Systems-doo-VirusTotal.png 719w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/07\/Information-Technology-Systems-doo-VirusTotal-300x169.png 300w\" sizes=\"(max-width: 719px) 100vw, 719px\" \/><\/a><\/p>\n<p>Generic.DAA, Unwanted-Program and \u0003\u00a0are some of the detection names.<\/p>\n<p>Did you also find a file signed by\u00a0<strong>Information Technology Systems doo<\/strong>? What kind of download was it? In my case, the download claimed to be the Flash Player installer.<\/p>\n<p>Update 2014-09-03: Found a file promoted as a Java installer, signed by\u00a0<strong>Information Technology Systems doo<\/strong>:<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/07\/Information-Technology-Systems-doo.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-1687\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/07\/Information-Technology-Systems-doo.png\" alt=\"Information Technology Systems doo\" width=\"948\" height=\"660\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/07\/Information-Technology-Systems-doo.png 948w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/07\/Information-Technology-Systems-doo-300x208.png 300w\" sizes=\"(max-width: 948px) 100vw, 948px\" \/><\/a><\/p>\n<p>The web page is hosted on softkopro.net. The file is called <a href=\"http:\/\/www.freefixer.com\/library\/file\/java_setup.exe-139518\/\">java_setup.exe<\/a> and is detected by 10 of the 55 anti-virus programs at VirusTotal.<\/p>\n<p>According to the web page, java_setup.exe is a downloader, rather than the real Java setup file:<\/p>\n<blockquote><p>&#8220;Coinis downloader is distributing a proprietary download manager that will take you to the official download of this program. Prior to taking you to the official download, we will offer optional sponsored software that you may be interested in. You are not required to install any additional software to receive your download.&#8221;<\/p><\/blockquote>\n<p>Update 2016-09-23: I&#8217;ve rescanned the\u00a0<a href=\"http:\/\/www.freefixer.com\/library\/file\/java_setup.exe-139518\/\">java_setup.exe<\/a>\u00a0file. Now the detection rate is\u00a0<span style=\"color: #ff0000;\">31<\/span>\/57. Based on the <a href=\"https:\/\/www.virustotal.com\/en\/analisis\/\/file\/a1e91b1ad5702aa8880a93fb8ca2c1185cfcdc14df90f0ce00774a0a1486e074\/analysis\/\">scan result<\/a> over at VirusTotal and by looking at the java_setup.exe executable file, it seems that the file contains\u00a0the <strong>InstallCore software<\/strong>\u00a0rather the Coinis downloader, contrary to what the web page at\u00a0softkopro.net stated.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Just wanted to give you the heads up on a publisher called\u00a0Information Technology Systems doo. According to the certificate, the publisher is located in Montenegro: This is the VirusTotal scan report for the\u00a0Information Technology Systems doo file: Generic.DAA, Unwanted-Program and \u0003\u00a0are some of the detection names. Did you also find a file signed by\u00a0Information Technology &hellip; <a href=\"https:\/\/www.freefixer.com\/b\/information-technology-systems-doo\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Information Technology Systems doo &#8211; VirusTotal Report<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[54],"tags":[152,104],"_links":{"self":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/1136"}],"collection":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/comments?post=1136"}],"version-history":[{"count":8,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/1136\/revisions"}],"predecessor-version":[{"id":8353,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/1136\/revisions\/8353"}],"wp:attachment":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/media?parent=1136"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/categories?post=1136"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/tags?post=1136"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}