{"id":7261,"date":"2015-09-09T08:47:00","date_gmt":"2015-09-09T08:47:00","guid":{"rendered":"http:\/\/www.freefixer.com\/b\/?p=7261"},"modified":"2015-09-09T08:47:00","modified_gmt":"2015-09-09T08:47:00","slug":"vid-play-33-detection-rate-outbrowse","status":"publish","type":"post","link":"https:\/\/www.freefixer.com\/b\/vid-play-33-detection-rate-outbrowse\/","title":{"rendered":"viD PLAY &#8211; 33% Detection Rate &#8211; OutBrowse"},"content":{"rendered":"<p>Hello readers! If you are a regular here on the FreeFixer blog, you know that I&#8217;ve been examining files that have a digital signature and bundle various types of potentially unwanted software. Today I found another publisher named <strong>viD PLAY<\/strong> that bundles some software.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/09\/viD-PLAY-publisher.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-7264\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/09\/viD-PLAY-publisher.png\" alt=\"viD PLAY publisher\" width=\"533\" height=\"326\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/09\/viD-PLAY-publisher.png 533w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/09\/viD-PLAY-publisher-300x183.png 300w\" sizes=\"(max-width: 533px) 100vw, 533px\" \/><\/a><\/p>\n<p>If you have a viD PLAY file on your computer you may have noticed that viD PLAY pops up as the publisher in the User Account Control dialog when running the file. The certificate is issued by thawte SHA256 Code Signing CA.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/09\/viD-PLAY-certificate.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-7263\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/09\/viD-PLAY-certificate.png\" alt=\"viD PLAY certificate\" width=\"384\" height=\"382\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/09\/viD-PLAY-certificate.png 384w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/09\/viD-PLAY-certificate-150x150.png 150w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/09\/viD-PLAY-certificate-300x298.png 300w\" sizes=\"(max-width: 384px) 100vw, 384px\" \/><\/a><\/p>\n<p>Thawte at the root in the certificate chain:<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/09\/viD-PLAY-cert-chain.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-7262\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/09\/viD-PLAY-cert-chain.png\" alt=\"viD PLAY cert chain\" width=\"337\" height=\"199\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/09\/viD-PLAY-cert-chain.png 337w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/09\/viD-PLAY-cert-chain-300x177.png 300w\" sizes=\"(max-width: 337px) 100vw, 337px\" \/><\/a><\/p>\n<p>After uploading the viD PLAY file &#8211; Player.exe &#8211; to <a title=\"How To Scan a File for Viruses with VirusTotal\" href=\"http:\/\/www.freefixer.com\/b\/scan-files-for-viruses-virustotal\/\">VirusTotal<\/a>, it was clear that it&#8217;s probably better to delete the file than running it. The detection rate was 33% and some of the detection names were: Downloader.UIA, PUP.Optional.Vidplay, Adware-OutBrowse.h and OutBrowse.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/09\/viD-PLAY-virustotal.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-7265\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/09\/viD-PLAY-virustotal.png\" alt=\"viD PLAY virustotal\" width=\"802\" height=\"434\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/09\/viD-PLAY-virustotal.png 802w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/09\/viD-PLAY-virustotal-300x162.png 300w\" sizes=\"(max-width: 802px) 100vw, 802px\" \/><\/a><\/p>\n<p>Did you also find a viD PLAY file? What kind of download was it? If you remember the download link, please post it in the comments below.<\/p>\n<p>Thank you for reading.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hello readers! If you are a regular here on the FreeFixer blog, you know that I&#8217;ve been examining files that have a digital signature and bundle various types of potentially unwanted software. Today I found another publisher named viD PLAY that bundles some software. If you have a viD PLAY file on your computer you &hellip; <a href=\"https:\/\/www.freefixer.com\/b\/vid-play-33-detection-rate-outbrowse\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">viD PLAY &#8211; 33% Detection Rate &#8211; OutBrowse<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[54],"tags":[716],"_links":{"self":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/7261"}],"collection":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/comments?post=7261"}],"version-history":[{"count":1,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/7261\/revisions"}],"predecessor-version":[{"id":7266,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/7261\/revisions\/7266"}],"wp:attachment":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/media?parent=7261"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/categories?post=7261"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/tags?post=7261"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}