{"id":3531,"date":"2014-12-09T16:09:13","date_gmt":"2014-12-09T16:09:13","guid":{"rendered":"http:\/\/www.freefixer.com\/b\/?p=3531"},"modified":"2018-05-29T12:01:13","modified_gmt":"2018-05-29T12:01:13","slug":"amgrup-llc-detection-amonetize","status":"publish","type":"post","link":"https:\/\/www.freefixer.com\/b\/amgrup-llc-detection-amonetize\/","title":{"rendered":"AMGRUP LLC &#8211; 9% Detection Rate &#8211; Amonetize"},"content":{"rendered":"<p>Hello readers! Just a short note on a publisher called <strong>AMGRUP LLC<\/strong>.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/12\/AMGRUP-LLC-publisher.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-3533\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/12\/AMGRUP-LLC-publisher.png\" alt=\"AMGRUP LLC publisher\" width=\"490\" height=\"287\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/12\/AMGRUP-LLC-publisher.png 490w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/12\/AMGRUP-LLC-publisher-300x175.png 300w\" sizes=\"(max-width: 490px) 100vw, 490px\" \/><\/a><\/p>\n<p>You can see who the signer is when double-clicking on an executable file. AMGRUP LLC appears in the publisher field in the dialog that pops up. The AMGRUP LLC certificate shows that the publisher is located in Kiev, Ukraine.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/12\/AMGRUP-LLC-certificate.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-3532\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/12\/AMGRUP-LLC-certificate.png\" alt=\"AMGRUP LLC certificate\" width=\"472\" height=\"614\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/12\/AMGRUP-LLC-certificate.png 472w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/12\/AMGRUP-LLC-certificate-230x300.png 230w\" sizes=\"(max-width: 472px) 100vw, 472px\" \/><\/a><\/p>\n<p>The issue is that FlashPlayer__6741_i1420381978_il207.exe is not an official Adobe Flash Player download. If it was, it would be digitally signed by <strong>Adobe Systems Incorporated<\/strong>. Here&#8217;s how the <strong>authentic Adobe Flash Player<\/strong> looks like when you double click on it. Notice that the &#8220;Verified publisher&#8221; says &#8220;Adobe Systems Incorporated&#8221;.<br \/>\n<a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/11\/Adobe-Systems-Incorporated-Adobe-Flashplayer-Installer.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-3187\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/11\/Adobe-Systems-Incorporated-Adobe-Flashplayer-Installer.png\" alt=\"Adobe Systems Incorporated - Adobe Flashplayer Installer\" width=\"534\" height=\"324\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/11\/Adobe-Systems-Incorporated-Adobe-Flashplayer-Installer.png 534w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/11\/Adobe-Systems-Incorporated-Adobe-Flashplayer-Installer-300x182.png 300w\" sizes=\"(max-width: 534px) 100vw, 534px\" \/><\/a><\/p>\n<p>5 of the anti-virus scanners detected the file. AhnLab-V3 names FlashPlayer__6741_i1420381978_il207.exe as <strong>PUP\/Win32.Amonetiz<\/strong>, Avira reports <strong>ADWARE\/Adware.Gen4<\/strong> and NANO-Antivirus classifies it as <strong>Riskware.Win32.Amonetize.djsswg<\/strong>.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/12\/AMGRUP-LLC-virustotal.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-3534\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/12\/AMGRUP-LLC-virustotal.png\" alt=\"AMGRUP LLC virustotal\" width=\"727\" height=\"441\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/12\/AMGRUP-LLC-virustotal.png 727w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/12\/AMGRUP-LLC-virustotal-300x181.png 300w\" sizes=\"(max-width: 727px) 100vw, 727px\" \/><\/a><\/p>\n<p>Did you also find an AMGRUP LLC? Do you remember the download link? Please post it in the comments below and I&#8217;ll upload it to <a title=\"How To Scan a File for Viruses with VirusTotal\" href=\"http:\/\/www.freefixer.com\/b\/scan-files-for-viruses-virustotal\/\">VirusTotal<\/a> to see if that one is also detected.<\/p>\n<p>Thanks for reading.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hello readers! Just a short note on a publisher called AMGRUP LLC. You can see who the signer is when double-clicking on an executable file. AMGRUP LLC appears in the publisher field in the dialog that pops up. The AMGRUP LLC certificate shows that the publisher is located in Kiev, Ukraine. The issue is that &hellip; <a href=\"https:\/\/www.freefixer.com\/b\/amgrup-llc-detection-amonetize\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">AMGRUP LLC &#8211; 9% Detection Rate &#8211; Amonetize<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[54],"tags":[157,304,305],"_links":{"self":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/3531"}],"collection":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/comments?post=3531"}],"version-history":[{"count":2,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/3531\/revisions"}],"predecessor-version":[{"id":3536,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/3531\/revisions\/3536"}],"wp:attachment":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/media?parent=3531"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/categories?post=3531"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/tags?post=3531"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}