{"id":6915,"date":"2015-08-11T10:46:11","date_gmt":"2015-08-11T10:46:11","guid":{"rendered":"http:\/\/www.freefixer.com\/b\/?p=6915"},"modified":"2018-05-29T11:57:26","modified_gmt":"2018-05-29T11:57:26","slug":"semen-korzuba-virustotal-33-detection-multiplug-trjgenetic-gen","status":"publish","type":"post","link":"https:\/\/www.freefixer.com\/b\/semen-korzuba-virustotal-33-detection-multiplug-trjgenetic-gen\/","title":{"rendered":"Semen Korzuba &#8211; VirusTotal: 33% Detection &#8211; MultiPlug, Trj\/Genetic.gen"},"content":{"rendered":"<p>Hello! Just a short post before I call it a day. I found yet another file that bundled a bunch of unwanted programs, and the file was signed by <strong>Semen Korzuba<\/strong>.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/08\/Semen-Korzuba-warning.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-6919\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/08\/Semen-Korzuba-warning.png\" alt=\"Semen Korzuba warning\" width=\"513\" height=\"306\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/08\/Semen-Korzuba-warning.png 513w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/08\/Semen-Korzuba-warning-300x178.png 300w\" sizes=\"(max-width: 513px) 100vw, 513px\" \/><\/a><\/p>\n<p>Windows will display Semen Korzuba as the publisher when running the file. The certificate is issued by Certum Code Signing CA.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/08\/Semen-Korzuba-cert-chain.png\"><img loading=\"lazy\" class=\"alignnone size-large wp-image-6917\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/08\/Semen-Korzuba-cert-chain.png\" alt=\"Semen Korzuba cert chain\" width=\"330\" height=\"179\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/08\/Semen-Korzuba-cert-chain.png 330w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/08\/Semen-Korzuba-cert-chain-300x162.png 300w\" sizes=\"(max-width: 330px) 100vw, 330px\" \/><\/a> <a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/08\/Semen-Korzuba-certificate.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-6918\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/08\/Semen-Korzuba-certificate.png\" alt=\"Semen Korzuba certificate\" width=\"389\" height=\"376\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/08\/Semen-Korzuba-certificate.png 389w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/08\/Semen-Korzuba-certificate-300x289.png 300w\" sizes=\"(max-width: 389px) 100vw, 389px\" \/><\/a><\/p>\n<p>The <a title=\"How To Scan a File for Viruses with VirusTotal\" href=\"http:\/\/www.freefixer.com\/b\/scan-files-for-viruses-virustotal\/\">VirusTotal<\/a> report shows that the Semen Korzuba file should be avoided, since Download Uc Browser V Handler Zip.exe is detected as <strong>TR\/Dropper.Gen<\/strong> by Avira, <strong>a variant of Win32\/Adware.MultiPlug.NU<\/strong> by ESET-NOD32, <strong>PUP.Optional.Multiplug<\/strong> by Malwarebytes, <strong>Trj\/Genetic.gen<\/strong> by Panda and <strong>MultiPlug (v)<\/strong> by VIPRE.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/08\/Semen-Korzuba-anti-virus-report.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-6916\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/08\/Semen-Korzuba-anti-virus-report.png\" alt=\"Semen Korzuba anti-virus report\" width=\"697\" height=\"451\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/08\/Semen-Korzuba-anti-virus-report.png 697w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/08\/Semen-Korzuba-anti-virus-report-300x194.png 300w\" sizes=\"(max-width: 697px) 100vw, 697px\" \/><\/a><\/p>\n<p>Did you also find a file digitally signed by Semen Korzuba? Where did you find it and are the anti-virus programs detecting it? Please share in the comments below.<\/p>\n<p>Thanks for reading.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hello! Just a short post before I call it a day. I found yet another file that bundled a bunch of unwanted programs, and the file was signed by Semen Korzuba. Windows will display Semen Korzuba as the publisher when running the file. The certificate is issued by Certum Code Signing CA. The VirusTotal report &hellip; <a href=\"https:\/\/www.freefixer.com\/b\/semen-korzuba-virustotal-33-detection-multiplug-trjgenetic-gen\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Semen Korzuba &#8211; VirusTotal: 33% Detection &#8211; MultiPlug, Trj\/Genetic.gen<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[54],"tags":[708,305],"_links":{"self":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/6915"}],"collection":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/comments?post=6915"}],"version-history":[{"count":1,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/6915\/revisions"}],"predecessor-version":[{"id":6920,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/6915\/revisions\/6920"}],"wp:attachment":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/media?parent=6915"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/categories?post=6915"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/tags?post=6915"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}