{"id":4620,"date":"2015-02-19T07:29:38","date_gmt":"2015-02-19T07:29:38","guid":{"rendered":"http:\/\/www.freefixer.com\/b\/?p=4620"},"modified":"2018-05-29T12:00:31","modified_gmt":"2018-05-29T12:00:31","slug":"best-standard-fried-cookie-ltd-installcore","status":"publish","type":"post","link":"https:\/\/www.freefixer.com\/b\/best-standard-fried-cookie-ltd-installcore\/","title":{"rendered":"Best Standard (Fried Cookie Ltd.) &#8211; 9% Detection Rate &#8211; InstallCore"},"content":{"rendered":"<p>Welcome! If you are a regular here on the FreeFixer blog you know that I&#8217;ve been looking on the certificates used to sign files that bundled various types of unwanted software. Today I found another certificate, used by a publisher called <strong>Best Standard (Fried Cookie Ltd.)<\/strong>.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/02\/Best-Standard-Certificate.png\"><img loading=\"lazy\" class=\"alignnone size-large wp-image-4623\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/02\/Best-Standard-Certificate.png\" alt=\"Best Standard Certificate\" width=\"440\" height=\"398\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/02\/Best-Standard-Certificate.png 440w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/02\/Best-Standard-Certificate-300x271.png 300w\" sizes=\"(max-width: 440px) 100vw, 440px\" \/><\/a><\/p>\n<p>To get more details on the publisher, you can view the embedded certificate by right-clicking on the file, and looking under the Digital Signatures tab. According to the certificate we can see that Best Standard (Fried Cookie Ltd.) seems to be located in Tel Aviv, Israel and that the certificate is issued by GlobalSign CodeSigning CA &#8211; G2.<\/p>\n<p>What caught my attention was that the download was called Skype_Setup.exe. This might look like an official <strong>Skype<\/strong> download, but it is not. If it was an official download, it would have been signed by <strong>Skype Software Sarl<\/strong>. Here&#8217;s how the <strong>authentic Skype<\/strong> looks like when you double click on it. Notice that the &#8220;Verified publisher&#8221; says &#8220;Skype Software Sarl&#8221;.<br \/>\n<a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/12\/Skype-Software-Sarl-publisher.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-3425\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/12\/Skype-Software-Sarl-publisher.png\" alt=\"Skype Software Sarl publisher\" width=\"479\" height=\"277\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/12\/Skype-Software-Sarl-publisher.png 479w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/12\/Skype-Software-Sarl-publisher-300x173.png 300w\" sizes=\"(max-width: 479px) 100vw, 479px\" \/><\/a><\/p>\n<p>When I uploaded the Best Standard (Fried Cookie Ltd.) file to <a title=\"How To Scan a File for Viruses with VirusTotal\" href=\"http:\/\/www.freefixer.com\/b\/scan-files-for-viruses-virustotal\/\">VirusTotal<\/a>, it came up with a 9% detection rate. The file is detected as <strong>Application.Win32.FriedCookie.CIRK<\/strong> by Comodo, <strong>a variant of Win32\/InstallCore.WX potentially unwanted<\/strong> by ESET-NOD32 and <strong>InstallCore (fs)<\/strong> by VIPRE.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/02\/Best-Standard-Fried-Cookie-Ltd.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-4621\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/02\/Best-Standard-Fried-Cookie-Ltd.png\" alt=\"Best Standard Fried Cookie Ltd\" width=\"745\" height=\"428\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/02\/Best-Standard-Fried-Cookie-Ltd.png 745w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/02\/Best-Standard-Fried-Cookie-Ltd-300x172.png 300w\" sizes=\"(max-width: 745px) 100vw, 745px\" \/><\/a><\/p>\n<p>Did you also find a file digitally signed by Best Standard (Fried Cookie Ltd.)? Where did you find it and are the anti-virus programs detecting it? Please share in the comments below.<\/p>\n<p>Thank you for reading.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Welcome! If you are a regular here on the FreeFixer blog you know that I&#8217;ve been looking on the certificates used to sign files that bundled various types of unwanted software. Today I found another certificate, used by a publisher called Best Standard (Fried Cookie Ltd.). To get more details on the publisher, you can &hellip; <a href=\"https:\/\/www.freefixer.com\/b\/best-standard-fried-cookie-ltd-installcore\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Best Standard (Fried Cookie Ltd.) &#8211; 9% Detection Rate &#8211; InstallCore<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[54],"tags":[372,252,251],"_links":{"self":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/4620"}],"collection":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/comments?post=4620"}],"version-history":[{"count":1,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/4620\/revisions"}],"predecessor-version":[{"id":4624,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/4620\/revisions\/4624"}],"wp:attachment":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/media?parent=4620"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/categories?post=4620"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/tags?post=4620"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}