{"id":8144,"date":"2015-11-24T18:24:20","date_gmt":"2015-11-24T18:24:20","guid":{"rendered":"http:\/\/www.freefixer.com\/b\/?p=8144"},"modified":"2018-05-29T11:55:39","modified_gmt":"2018-05-29T11:55:39","slug":"setupflash-new-media-holdings-ltd-18-detection-rate","status":"publish","type":"post","link":"https:\/\/www.freefixer.com\/b\/setupflash-new-media-holdings-ltd-18-detection-rate\/","title":{"rendered":"SetupFlash (New Media Holdings Ltd.) &#8211; 18% Detection Rate"},"content":{"rendered":"<p>Hello readers! Just wanted to let you know about a publisher called <strong>SetupFlash (New Media Holdings Ltd.)<\/strong> before going back to writing some code for FreeFixer.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/11\/SetupFlash-New-Media-Holdings-Ltd-publisher.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-8146\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/11\/SetupFlash-New-Media-Holdings-Ltd-publisher.png\" alt=\"SetupFlash New Media Holdings Ltd publisher\" width=\"500\" height=\"293\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/11\/SetupFlash-New-Media-Holdings-Ltd-publisher.png 500w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/11\/SetupFlash-New-Media-Holdings-Ltd-publisher-300x176.png 300w\" sizes=\"(max-width: 500px) 100vw, 500px\" \/><\/a><\/p>\n<p>This is how it looks when double-clicking on the file and SetupFlash (New Media Holdings Ltd.) appears as the publisher. To get more details on the publisher, you can view the certificate by right-clicking on the file, and looking under the Digital Signatures tab. According to the certificate we can see that SetupFlash (New Media Holdings Ltd.) seems to be located in Israel and that the certificate is issued by GlobalSign CodeSigning CA &#8211; G2.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/11\/SetupFlash-New-Media-Holdings-Ltd.-cert.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-8145\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/11\/SetupFlash-New-Media-Holdings-Ltd.-cert.png\" alt=\"SetupFlash (New Media Holdings Ltd.) cert\" width=\"360\" height=\"370\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/11\/SetupFlash-New-Media-Holdings-Ltd.-cert.png 360w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/11\/SetupFlash-New-Media-Holdings-Ltd.-cert-292x300.png 292w\" sizes=\"(max-width: 360px) 100vw, 360px\" \/><\/a><\/p>\n<p>What caught my attention was that the download was called chrome-download.exe. This might look like an official <strong>Google Chrome<\/strong> download, but it is not. If it was an official download, it should be signed by <strong>Google Inc.<\/strong>. Here&#8217;s how the <strong>authentic Google Chrome<\/strong> looks like when you double click on it. Notice that the &#8220;Verified publisher&#8221; says &#8220;Google Inc&#8221;.<br \/>\n<a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/12\/Chrome-Google-Inc-publisher.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-3423\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/12\/Chrome-Google-Inc-publisher.png\" alt=\"Chrome Google Inc publisher\" width=\"483\" height=\"280\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/12\/Chrome-Google-Inc-publisher.png 483w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/12\/Chrome-Google-Inc-publisher-300x173.png 300w\" sizes=\"(max-width: 483px) 100vw, 483px\" \/><\/a><\/p>\n<p>If you are considering to run the SetupFlash (New Media Holdings Ltd.) signed file, I&#8217;ll advice you not to. Delete it instead. Just check out detection list by some of the anti-virus program:<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/11\/SetupFlash-New-Media-Holdings-Ltd.-report.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-8147\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/11\/SetupFlash-New-Media-Holdings-Ltd.-report.png\" alt=\"SetupFlash New Media Holdings Ltd. report\" width=\"835\" height=\"443\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/11\/SetupFlash-New-Media-Holdings-Ltd.-report.png 835w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/11\/SetupFlash-New-Media-Holdings-Ltd.-report-300x159.png 300w\" sizes=\"(max-width: 835px) 100vw, 835px\" \/><\/a><\/p>\n<p>Ikarus classifies chrome-download.exe as <strong>PUA.InstallCore<\/strong>, VIPRE detects it as <strong>InstallCore (fs)<\/strong>, Malwarebytes detects it as <strong>PUP.Optional.InstallCore<\/strong> and Sophos reports <strong>Install Core Click run software (PUA)<\/strong>.<\/p>\n<p>Did you also find a SetupFlash (New Media Holdings Ltd.) file?<\/p>\n<p>Thank you for reading.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hello readers! Just wanted to let you know about a publisher called SetupFlash (New Media Holdings Ltd.) before going back to writing some code for FreeFixer. This is how it looks when double-clicking on the file and SetupFlash (New Media Holdings Ltd.) appears as the publisher. To get more details on the publisher, you can &hellip; <a href=\"https:\/\/www.freefixer.com\/b\/setupflash-new-media-holdings-ltd-18-detection-rate\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">SetupFlash (New Media Holdings Ltd.) &#8211; 18% Detection Rate<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[1],"tags":[252,251],"_links":{"self":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/8144"}],"collection":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/comments?post=8144"}],"version-history":[{"count":1,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/8144\/revisions"}],"predecessor-version":[{"id":8148,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/8144\/revisions\/8148"}],"wp:attachment":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/media?parent=8144"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/categories?post=8144"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/tags?post=8144"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}