{"id":7700,"date":"2015-10-07T08:14:28","date_gmt":"2015-10-07T08:14:28","guid":{"rendered":"http:\/\/www.freefixer.com\/b\/?p=7700"},"modified":"2018-05-29T11:55:44","modified_gmt":"2018-05-29T11:55:44","slug":"llc-deka-soft-9-detection-rate-pua-bundler-amonetize-trojan-win32-agent-dxmgor","status":"publish","type":"post","link":"https:\/\/www.freefixer.com\/b\/llc-deka-soft-9-detection-rate-pua-bundler-amonetize-trojan-win32-agent-dxmgor\/","title":{"rendered":"LLC &#8220;DEKA-SOFT&#8221; &#8211; 9% Detection Rate &#8211; PUA.Bundler.Amonetize \/ Trojan.Win32.Agent.dxmgor"},"content":{"rendered":"<p>Hi there! Was looking for some downloads to play around with and found one, digitally signed by <strong>LLC &#8220;DEKA-SOFT&#8221;:<\/strong><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/10\/LLC-DEKA-SOFT-warning.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-7706\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/10\/LLC-DEKA-SOFT-warning.png\" alt=\"LLC DEKA-SOFT warning\" width=\"501\" height=\"297\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/10\/LLC-DEKA-SOFT-warning.png 501w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/10\/LLC-DEKA-SOFT-warning-300x178.png 300w\" sizes=\"(max-width: 501px) 100vw, 501px\" \/><\/a><\/p>\n<p>You can see who the signer is when double-clicking on an executable file. LLC &#8220;DEKA-SOFT&#8221; appears in the publisher field in the dialog that pops up. It is also possible to check a digital signature by looking at a file&#8217;s properties. Here&#8217;s a screenshot of the LLC &#8220;DEKA-SOFT&#8221; certificate.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/10\/LLC-DEKA-SOFT-cert.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-7705\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/10\/LLC-DEKA-SOFT-cert.png\" alt=\"LLC DEKA-SOFT cert\" width=\"400\" height=\"410\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/10\/LLC-DEKA-SOFT-cert.png 400w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/10\/LLC-DEKA-SOFT-cert-293x300.png 293w\" sizes=\"(max-width: 400px) 100vw, 400px\" \/><\/a><\/p>\n<p>According to the certificate, DEKASOFT is located <strong>Ukraine<\/strong>. Comodo has issued the certificated back in July.<\/p>\n<p>The reason I&#8217;m writing this blog post is that the LLC DEKA-SOFT file is detected by some of the anti-virus software at <a title=\"How To Scan a File for Viruses with VirusTotal\" href=\"http:\/\/www.freefixer.com\/b\/scan-files-for-viruses-virustotal\/\">VirusTotal<\/a>. Ikarus reports <strong>PUA.Bundler.Amonetize<\/strong>, ESET-NOD32 names the file as <strong>a variant of Win32\/Amonetize.JT potentially unwanted<\/strong>, NANO-Antivirus calls it <strong>Trojan.Win32.Agent.dxmgor<\/strong> and Rising detects it as <strong>PE:Malware.RDM.14!5.14[F1]<\/strong>.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/10\/LLC-DEKA-SOFT-anti-virus-report.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-7704\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/10\/LLC-DEKA-SOFT-anti-virus-report.png\" alt=\"LLC DEKA-SOFT anti-virus report\" width=\"760\" height=\"446\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/10\/LLC-DEKA-SOFT-anti-virus-report.png 760w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/10\/LLC-DEKA-SOFT-anti-virus-report-300x176.png 300w\" sizes=\"(max-width: 760px) 100vw, 760px\" \/><\/a><\/p>\n<p>Did you also find a LLC &#8220;DEKA-SOFT&#8221; file? Do you remember where you downloaded it?<\/p>\n<p>Thank you for reading.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hi there! Was looking for some downloads to play around with and found one, digitally signed by LLC &#8220;DEKA-SOFT&#8221;: You can see who the signer is when double-clicking on an executable file. LLC &#8220;DEKA-SOFT&#8221; appears in the publisher field in the dialog that pops up. It is also possible to check a digital signature by &hellip; <a href=\"https:\/\/www.freefixer.com\/b\/llc-deka-soft-9-detection-rate-pua-bundler-amonetize-trojan-win32-agent-dxmgor\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">LLC &#8220;DEKA-SOFT&#8221; &#8211; 9% Detection Rate &#8211; PUA.Bundler.Amonetize \/ Trojan.Win32.Agent.dxmgor<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[54],"tags":[126,726,305],"_links":{"self":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/7700"}],"collection":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/comments?post=7700"}],"version-history":[{"count":1,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/7700\/revisions"}],"predecessor-version":[{"id":7707,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/7700\/revisions\/7707"}],"wp:attachment":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/media?parent=7700"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/categories?post=7700"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/tags?post=7700"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}