{"id":2242,"date":"2014-10-22T06:06:28","date_gmt":"2014-10-22T06:06:28","guid":{"rendered":"http:\/\/www.freefixer.com\/b\/?p=2242"},"modified":"2018-05-29T12:01:57","modified_gmt":"2018-05-29T12:01:57","slug":"click-yes-virustotal-report","status":"publish","type":"post","link":"https:\/\/www.freefixer.com\/b\/click-yes-virustotal-report\/","title":{"rendered":"Click Yes &#8211; 6% Detection Rate at VirusTotal"},"content":{"rendered":"<p>Hi there! If you&#8217;ve been following my recent posts here on the FreeFixer blog, you know that I&#8217;ve been looking at files that have a valid digital signature and bundle various types of potentially unwanted programs. This morning\u00a0I found another publisher named <strong>Click Yes<\/strong>.\u00a0The following screenshot shows the User Account Control dialog when running the Click Yes file:<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/Click-Yes-publisher.png\"><img loading=\"lazy\" class=\"alignnone wp-image-2244 size-full\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/Click-Yes-publisher.png\" alt=\"Click Yes publisher in the uac dialog\" width=\"510\" height=\"301\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/Click-Yes-publisher.png 510w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/Click-Yes-publisher-300x177.png 300w\" sizes=\"(max-width: 510px) 100vw, 510px\" \/><\/a><\/p>\n<p>By looking at the certificate we can see that <strong>Click Yes<\/strong> appears to be located in <strong>Dublin<\/strong>, <strong>Ireland<\/strong>. The certificate is quite new. It&#8217;s validity period started yesterday, on the 21st of October.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/Click-Yes-certificate.png\"><img loading=\"lazy\" class=\"alignnone wp-image-2243 size-full\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/Click-Yes-certificate.png\" alt=\"Click Yes certificate\" width=\"502\" height=\"541\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/Click-Yes-certificate.png 502w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/Click-Yes-certificate-278x300.png 278w\" sizes=\"(max-width: 502px) 100vw, 502px\" \/><\/a><\/p>\n<p>The VirusTotal report shows that the Click Yes file should probably be avoided, since setup.exe is detected as <strong>APPL\/Downloader.Gen<\/strong> by Avira, <strong>Trojan.Packed.29192<\/strong> by DrWeb and <strong>Win32\/OutBrowse.AY<\/strong> by ESET-NOD32. The detection rate is only 6% which is quite low.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/Click-Yes-virustotal-report.png\"><img loading=\"lazy\" class=\"alignnone wp-image-2245 size-full\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/Click-Yes-virustotal-report.png\" alt=\"Click Yes virus total report - 6% detection rate\" width=\"654\" height=\"390\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/Click-Yes-virustotal-report.png 654w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/Click-Yes-virustotal-report-300x178.png 300w\" sizes=\"(max-width: 654px) 100vw, 654px\" \/><\/a><\/p>\n<p>Did you also find a Click Yes file? What kind of download was it? If you remember the download link, please post it in the comments below and I&#8217;ll upload it to VirusTotal to see if the detection rate is improved.<\/p>\n<p>Hope this blog post helped you avoid some unwanted software on your machine.<\/p>\n<p>Thanks for reading.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hi there! If you&#8217;ve been following my recent posts here on the FreeFixer blog, you know that I&#8217;ve been looking at files that have a valid digital signature and bundle various types of potentially unwanted programs. This morning\u00a0I found another publisher named Click Yes.\u00a0The following screenshot shows the User Account Control dialog when running the &hellip; <a href=\"https:\/\/www.freefixer.com\/b\/click-yes-virustotal-report\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Click Yes &#8211; 6% Detection Rate at VirusTotal<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[54],"tags":[172],"_links":{"self":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/2242"}],"collection":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/comments?post=2242"}],"version-history":[{"count":1,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/2242\/revisions"}],"predecessor-version":[{"id":2246,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/2242\/revisions\/2246"}],"wp:attachment":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/media?parent=2242"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/categories?post=2242"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/tags?post=2242"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}