{"id":6978,"date":"2015-08-16T06:07:36","date_gmt":"2015-08-16T06:07:36","guid":{"rendered":"http:\/\/www.freefixer.com\/b\/?p=6978"},"modified":"2018-05-29T11:57:26","modified_gmt":"2018-05-29T11:57:26","slug":"tea-time-biscuits-21-detection-rate-downloadadmin-jaik","status":"publish","type":"post","link":"https:\/\/www.freefixer.com\/b\/tea-time-biscuits-21-detection-rate-downloadadmin-jaik\/","title":{"rendered":"TEA TIME BISCUITS &#8211; 21% Detection Rate &#8211; DownloadAdmin \/ Jaik"},"content":{"rendered":"<p>Welcome! Just wanted to give you the heads up on a file called &#8220;additionaloffers-setup[1].exe&#8221; that&#8217;s digitally signed by <strong>TEA TIME BISCUITS<\/strong>.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/08\/TEA-TIME-BISCUITS-certificate.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-6980\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/08\/TEA-TIME-BISCUITS-certificate.png\" alt=\"TEA TIME BISCUITS certificate\" width=\"382\" height=\"372\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/08\/TEA-TIME-BISCUITS-certificate.png 382w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/08\/TEA-TIME-BISCUITS-certificate-300x292.png 300w\" sizes=\"(max-width: 382px) 100vw, 382px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>I found this file on my lab machine after trying out a download from CNet&#8217;s Download.com site.<\/p>\n<p>You can view the\u00a0certificate shown above by right-clicking on the file, choosing properties and then clicking on the Digital Signatures tab. According to the embedded certificate we can see that TEA TIME BISCUITS seems to be located in San Fransisco, California, US and that the certificate is issued by VeriSign Class 3 Code Signing 2010 CA.<\/p>\n<p>So, what the issue with the TEA TIME BISCUITS file?\u00a0Just check out detection list by some of the anti-virus program:<\/p>\n<p>F-Secure reports additionaloffers-setup[1].exe as <strong>Gen:Variant.Application.Jaik<\/strong>, GData detects it as <strong>Gen:Variant.Application.Jaik.8223<\/strong> and Malwarebytes calls it <strong>PUP.Optional.DownloadAdmin<\/strong>.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/08\/TEA-TIME-BISCUITS-anti-virus-report.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-6979\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/08\/TEA-TIME-BISCUITS-anti-virus-report.png\" alt=\"TEA TIME BISCUITS anti-virus report\" width=\"817\" height=\"431\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/08\/TEA-TIME-BISCUITS-anti-virus-report.png 817w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/08\/TEA-TIME-BISCUITS-anti-virus-report-300x158.png 300w\" sizes=\"(max-width: 817px) 100vw, 817px\" \/><\/a><\/p>\n<p>Did you also find a TEA TIME BISCUITS file? Do you remember where you downloaded it?<\/p>\n<p>Thank you for reading.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Welcome! Just wanted to give you the heads up on a file called &#8220;additionaloffers-setup[1].exe&#8221; that&#8217;s digitally signed by TEA TIME BISCUITS. &nbsp; I found this file on my lab machine after trying out a download from CNet&#8217;s Download.com site. You can view the\u00a0certificate shown above by right-clicking on the file, choosing properties and then clicking &hellip; <a href=\"https:\/\/www.freefixer.com\/b\/tea-time-biscuits-21-detection-rate-downloadadmin-jaik\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">TEA TIME BISCUITS &#8211; 21% Detection Rate &#8211; DownloadAdmin \/ Jaik<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[414],"tags":[167,218,673,510],"_links":{"self":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/6978"}],"collection":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/comments?post=6978"}],"version-history":[{"count":1,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/6978\/revisions"}],"predecessor-version":[{"id":6981,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/6978\/revisions\/6981"}],"wp:attachment":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/media?parent=6978"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/categories?post=6978"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/tags?post=6978"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}