{"id":2292,"date":"2014-10-23T09:04:08","date_gmt":"2014-10-23T09:04:08","guid":{"rendered":"http:\/\/www.freefixer.com\/b\/?p=2292"},"modified":"2018-05-29T12:01:57","modified_gmt":"2018-05-29T12:01:57","slug":"fileangels-publisher","status":"publish","type":"post","link":"https:\/\/www.freefixer.com\/b\/fileangels-publisher\/","title":{"rendered":"Fileangels &#8211; Detected as IBryte and OptimunInstaller"},"content":{"rendered":"<p>Welcome! Just a note on a publisher called <strong>Fileangels<\/strong>. The Fileangels download &#8211; setup.exe &#8211; was detected when I uploaded it to VirusTotal. Did you also find a download by Fileangels? Was it also detected when you uploaded it to VirusTotal?<\/p>\n<p>This is how <strong>Fileangels<\/strong> appears when running the file:<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/fileangels-publisher.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-2294\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/fileangels-publisher.png\" alt=\"fileangels publisher\" width=\"483\" height=\"278\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/fileangels-publisher.png 483w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/fileangels-publisher-300x172.png 300w\" sizes=\"(max-width: 483px) 100vw, 483px\" \/><\/a><\/p>\n<p>By looking at the certificate we can see that Fileangels appears to be located in Kansas City, USA.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/Fileangels-certificate.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-2293\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/Fileangels-certificate.png\" alt=\"Fileangels certificate\" width=\"509\" height=\"424\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/Fileangels-certificate.png 509w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/Fileangels-certificate-300x249.png 300w\" sizes=\"(max-width: 509px) 100vw, 509px\" \/><\/a><\/p>\n<p>The reason I&#8217;m writing this blog post is that the Fileangels file is detected by some of the anti-malware scanners at <a href=\"http:\/\/www.freefixer.com\/b\/scan-files-for-viruses-virustotal\/\">VirusTotal<\/a>. AVG detects setup.exe as <strong>AdPlugin.BNR<\/strong>, Fortinet detects it as <strong>W32\/Zbot.AAN!tr<\/strong>, Kaspersky detects it as <strong>Trojan.Win32.Badur.jukw<\/strong>, Malwarebytes reports <strong>PUP.Optional.OptimunInstaller<\/strong> and McAfee detects it as <strong>IBryte-FRT<\/strong>. In addition, the Fileangels download was also promoted as a &#8220;Java Update&#8221;.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/fileangels-virustotal-ibryte.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-2295\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/fileangels-virustotal-ibryte.png\" alt=\"fileangels virustotal ibryte\" width=\"725\" height=\"498\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/fileangels-virustotal-ibryte.png 725w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/fileangels-virustotal-ibryte-300x206.png 300w\" sizes=\"(max-width: 725px) 100vw, 725px\" \/><\/a><\/p>\n<p>Did you also find a file digitally signed by Fileangels? Where did you find it and are the anti-virus programs detecting it? Please share in the comments below.<\/p>\n<p>Thanks for reading.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Welcome! Just a note on a publisher called Fileangels. The Fileangels download &#8211; setup.exe &#8211; was detected when I uploaded it to VirusTotal. Did you also find a download by Fileangels? Was it also detected when you uploaded it to VirusTotal? This is how Fileangels appears when running the file: By looking at the certificate &hellip; <a href=\"https:\/\/www.freefixer.com\/b\/fileangels-publisher\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Fileangels &#8211; Detected as IBryte and OptimunInstaller<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[54],"tags":[152,184,199],"_links":{"self":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/2292"}],"collection":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/comments?post=2292"}],"version-history":[{"count":5,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/2292\/revisions"}],"predecessor-version":[{"id":2727,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/2292\/revisions\/2727"}],"wp:attachment":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/media?parent=2292"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/categories?post=2292"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/tags?post=2292"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}