{"id":2918,"date":"2014-11-14T11:13:54","date_gmt":"2014-11-14T11:13:54","guid":{"rendered":"http:\/\/www.freefixer.com\/b\/?p=2918"},"modified":"2018-05-29T12:01:51","modified_gmt":"2018-05-29T12:01:51","slug":"svan-trans-llc-25-detection-rate","status":"publish","type":"post","link":"https:\/\/www.freefixer.com\/b\/svan-trans-llc-25-detection-rate\/","title":{"rendered":"SVAN TRANS LLC &#8211; 25% Detection Rate"},"content":{"rendered":"<p>Hi there! Just wanted to give you the heads-up on suspicious file I found right now before having my lunch. The file is named FlashPlayer__6741_i1404957756_il13.exe and digitally signed by <strong>SVAN TRANS LLC<\/strong>.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/11\/SVAN-TRANS-LLC-publisher1.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-2920\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/11\/SVAN-TRANS-LLC-publisher1.png\" alt=\"SVAN TRANS LLC publisher\" width=\"539\" height=\"326\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/11\/SVAN-TRANS-LLC-publisher1.png 539w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/11\/SVAN-TRANS-LLC-publisher1-300x181.png 300w\" sizes=\"(max-width: 539px) 100vw, 539px\" \/><\/a><\/p>\n<p>You can also see the SVAN TRANS LLC certificate by looking under the Digital Signature tab on the file&#8217;s properties. According to the certificate, SVAN TRANS LLC is located in Kiev, Ukraine.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/11\/SVAN-TRANS-LLC-certificate1.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-2919\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/11\/SVAN-TRANS-LLC-certificate1.png\" alt=\"SVAN TRANS LLC certificate\" width=\"516\" height=\"461\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/11\/SVAN-TRANS-LLC-certificate1.png 516w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/11\/SVAN-TRANS-LLC-certificate1-300x268.png 300w\" sizes=\"(max-width: 516px) 100vw, 516px\" \/><\/a><\/p>\n<p>The issue is that FlashPlayer__6741_i1404957756_il13.exe is <strong>not an official Flash Player<\/strong> download. If it was, it would be digitally signed by <strong>Adobe Systems Incorporated<\/strong>, and not by some unknown company from Ukraine.<\/p>\n<p>25% of the scanners detected the file. The FlashPlayer__6741_i1404957756_il13.exe file is detected as <strong>PUA.Amonetize!<\/strong> by Agnitum, <strong>Gen:Variant.Application.Jaik<\/strong> by F-Secure and <strong>PUP.Optional.Amonetize<\/strong> by Malwarebytes. Thanks to <a title=\"How To Scan a File for Viruses with VirusTotal\" href=\"http:\/\/www.freefixer.com\/b\/scan-files-for-viruses-virustotal\/\">VirusTotal<\/a> for the scan report.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/11\/svan-trans-llc-virustotal.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-2921\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/11\/svan-trans-llc-virustotal.png\" alt=\"svan trans llc virustotal\" width=\"674\" height=\"505\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/11\/svan-trans-llc-virustotal.png 674w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/11\/svan-trans-llc-virustotal-300x224.png 300w\" sizes=\"(max-width: 674px) 100vw, 674px\" \/><\/a><\/p>\n<p>Since some of the anti-virus programs detected the SVAN TRANS LLC file, I got curious and decided to test it to see what it installed. After stepping though the installer, <a title=\"Salus Adware \u2013 \u201cAds by Salus\u201d Removal Instructions\" href=\"http:\/\/www.freefixer.com\/b\/remove-salus-adware\/\">Salus Net Protector<\/a>, <a title=\"Remove RocketTab \u2013 \u201cAds by RocketTab\u201d Removal Instructions\" href=\"http:\/\/www.freefixer.com\/b\/remove-rockettab-ads\/\">RocketTab<\/a> and My Start Search were disclosed.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/11\/SVAN-TRANS-Salus1.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-2923\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/11\/SVAN-TRANS-Salus1.png\" alt=\"SVAN TRANS Salus\" width=\"510\" height=\"74\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/11\/SVAN-TRANS-Salus1.png 510w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/11\/SVAN-TRANS-Salus1-300x43.png 300w\" sizes=\"(max-width: 510px) 100vw, 510px\" \/><\/a> <a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/11\/SVAN-Trans-Rockettab1.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-2922\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/11\/SVAN-Trans-Rockettab1.png\" alt=\"SVAN Trans Rockettab\" width=\"616\" height=\"108\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/11\/SVAN-Trans-Rockettab1.png 616w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/11\/SVAN-Trans-Rockettab1-300x52.png 300w\" sizes=\"(max-width: 616px) 100vw, 616px\" \/><\/a><\/p>\n<p>Did you also find an SVAN TRANS LLC? Do you remember the download link? Please post it in the comments below and I&#8217;ll upload it to VirusTotal to see if that one is also detected.<\/p>\n<p>Thanks for reading.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hi there! Just wanted to give you the heads-up on suspicious file I found right now before having my lunch. The file is named FlashPlayer__6741_i1404957756_il13.exe and digitally signed by SVAN TRANS LLC. You can also see the SVAN TRANS LLC certificate by looking under the Digital Signature tab on the file&#8217;s properties. According to the &hellip; <a href=\"https:\/\/www.freefixer.com\/b\/svan-trans-llc-25-detection-rate\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">SVAN TRANS LLC &#8211; 25% Detection Rate<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[54],"tags":[126,186,218],"_links":{"self":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/2918"}],"collection":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/comments?post=2918"}],"version-history":[{"count":1,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/2918\/revisions"}],"predecessor-version":[{"id":2924,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/2918\/revisions\/2924"}],"wp:attachment":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/media?parent=2918"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/categories?post=2918"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/tags?post=2918"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}