{"id":1284,"date":"2014-08-07T22:06:09","date_gmt":"2014-08-07T22:06:09","guid":{"rendered":"http:\/\/www.freefixer.com\/b\/?p=1284"},"modified":"2018-05-29T12:02:48","modified_gmt":"2018-05-29T12:02:48","slug":"file-monarch-java_setup-exe","status":"publish","type":"post","link":"https:\/\/www.freefixer.com\/b\/file-monarch-java_setup-exe\/","title":{"rendered":"File Monarch &#038; java_setup.exe &#8211; Stay away from it &#8211; 34% detection rate"},"content":{"rendered":"<p>If you are a regular here on the FreeFixer blog you know that I&#8217;ve been looking on the certificates used to sign files that bundled various types of unwanted software.<\/p>\n<p>While I was looking around on some recently submitted files here on <a href=\"http:\/\/www.freefixer.com\">freefixer.com<\/a> I found a file called <a href=\"http:\/\/www.freefixer.com\/library\/file\/java_setup.exe-136402\/\">java_setup.exe<\/a> signed by a company called <strong>File Monarch<\/strong>. The problem here is that if this really was a setup file for <a href=\"https:\/\/www.java.com\/en\/\">Java<\/a>, it would have been digitally signed by <a href=\"http:\/\/www.oracle.com\/\">Oracle<\/a> and not by \u00a0some unknown company. This looks very suspicious. And the VirusTotal report shows that the <strong>File Monarch<\/strong>\u00a0file should be avoided, since <strong>java_setup.exe<\/strong> is detected as <strong>Adware.IBryte<\/strong>, <strong>Optimum Installer<\/strong> and <strong>Trojan.Win32.Buzus<\/strong>.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/08\/File-Monarch-java_setup.exe-VirusTotal-report.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-1290\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/08\/File-Monarch-java_setup.exe-VirusTotal-report.png\" alt=\"File Monarch - java_setup.exe VirusTotal report\" width=\"731\" height=\"353\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/08\/File-Monarch-java_setup.exe-VirusTotal-report.png 731w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/08\/File-Monarch-java_setup.exe-VirusTotal-report-300x144.png 300w\" sizes=\"(max-width: 731px) 100vw, 731px\" \/><\/a><\/p>\n<p>This tactic appears to be pretty common to get users to install something that they didn&#8217;t want: Pop up some file and claim that Java or the Flash Player needs to be updated.<\/p>\n<p>Well, hope that helped you avoid some adware or whatever this <strong>java_setup.exe<\/strong> file would install.<\/p>\n<p>Did you also find some file signed by <strong>File Monarch<\/strong>, or a file falsely claiming to be a Java setup file? Where did you find them?<\/p>\n<p>I&#8217;ll dig around a bit more in the FreeFixer database to see if there&#8217;s some other faked Java setup files.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>If you are a regular here on the FreeFixer blog you know that I&#8217;ve been looking on the certificates used to sign files that bundled various types of unwanted software. While I was looking around on some recently submitted files here on freefixer.com I found a file called java_setup.exe signed by a company called File &hellip; <a href=\"https:\/\/www.freefixer.com\/b\/file-monarch-java_setup-exe\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">File Monarch &#038; java_setup.exe &#8211; Stay away from it &#8211; 34% detection rate<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[3,54],"tags":[141],"_links":{"self":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/1284"}],"collection":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/comments?post=1284"}],"version-history":[{"count":9,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/1284\/revisions"}],"predecessor-version":[{"id":1294,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/1284\/revisions\/1294"}],"wp:attachment":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/media?parent=1284"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/categories?post=1284"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/tags?post=1284"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}