Tag Archives: Israel

Remove rvfrm2007.com Pop Up Ads

Did you just get a pop-up from rvfrm2007.com and ask yourself where it came from? Did the rvfrm2007.com ad appear to have been popped up from a web site that under normal circumstances don’t use aggressive advertising such as pop-up windows? Or did the rvfrm2007.com pop-up show up while you clicked a link on one of the major search engines, such as Google, Bing or Yahoo?

Here is how the rvfrm2007.com ad looked like on my machine when it appeared in a new tab:

rvfrm2007.com pop up

The pop up mentions the ad124m.adk2.net domain. After a while, I was redirected to a igame.com ad.

If you also see this on your computer, you presumably have some adware installed on your computer that pops up the rvfrm2007.com ads. Contacting the site owner would be a waste of time. The ads are not coming from them. I’ll do my best to help you remove the rvfrm2007.com pop-up in this blog post.

For those that are new to the blog: Recently I dedicated some of my lab computers and wilfully installed a few adware programs on them. Since then I have been following the behaviour on these machines to see what kinds of advertisements that are displayed. I’m also looking on other interesting things such as if the adware updates itself, or if it downloads additional unwanted software on the machines. I first observed the rvfrm2007.com pop-up on one of these lab machines.

rvfrm2007.com resolves to the 173.192.117.80 IP address. rvfrm2007.com was created on 2015-01-01. Here’s some of the WHOIS info:

Registrant Name: DNS ADMIN
Registrant Organization: MYADWISE LTD.
Registrant Street: HAPLADA 5
Registrant City: OR YEHUDA
Registrant Country: IL

So, how do you remove the rvfrm2007.com pop-up ads? On the machine where I got the rvfrm2007.com ads I had BlockAndSurf, TinyWallet and BrowserWarden installed. I removed them with FreeFixer and that stopped the rvfrm2007.com pop-ups and all the other ads I was getting in Mozilla Firefox.

The issue with this type of pop-up is that it can be initiated by many variants of adware. This makes it impossible to say exactly what you need to remove to stop the pop-ups.

So, what can be done to solve the problem? To remove the rvfrm2007.com popup ads you need to review your system for adware or other types of unwanted software and uninstall it. Here’s my suggested removal procedure:

The first thing I would do to remove the rvfrm2007.com pop-ups is to examine the programs installed on the machine, by opening the “Uninstall programs” dialog. You can reach this dialog from the Windows Control Panel. If you are using one of the more recent versions of Windows you can just type in “uninstall” in the Control Panel’s search field to find that dialog:
Uninstall a program search

Click on the “Uninstall a program” link and the Uninstall programs dialog will open up:
Uninstall a program dialog

Do you see something suspicious listed there or something that you don’t remember installing? Tip: Sort on the “Installed On” column to see if something was installed about the same time as you started getting the rvfrm2007.com pop-ups.

The next thing to check would be your browser’s add-ons. Adware often appear under the add-ons dialog in Google Chrome, Mozilla Firefox, Internet Explorer, Safari or Opera. Is there anything that looks suspicious? Something that you don’t remember installing?
Firefox add-ons manager

I think you will be able to track down and remove the adware with the steps outlined above, but in case that did not work you can try the FreeFixer removal tool to identify and remove the adware. FreeFixer is a freeware tool that I started develop about 8 years ago. Freefixer is a tool built to manually track down and remove unwanted software. When you’ve found the unwanted files you can simply tick a checkbox and click on the Fix button to remove the unwanted file.

FreeFixer’s removal feature is not locked down like many other removal tools out there. It will not require you to pay a fee just when you are about to remove the unwanted files.

And if you’re having difficulties determining if a file is legit or unsafe in FreeFixer’s scan report, click on the More Info link for the file. That will open up your web browser with a page which contains additional information about the file. On that web page, check out the VirusTotal report which can be quite useful:

FreeFixer More Info link example
An example of FreeFixer’s “More Info” links. Click for full size.

Here you can see FreeFixer in action removing pop-up ads:

Did you find any adware on your machine? Did that stop the rvfrm2007.com ads? Please post the name of the adware you uninstalled from your machine in the comment below.

Thank you!

Funnel Connector (Fried Cookie Ltd) – 7% Detection Rate By VirusTotal – InstallCore

Welcome! Just wanted to give you the heads up on a file called Skype_Setup.exe that’s digitally signed by Funnel Connector (Fried Cookie Ltd.).

Funnel Connector Fried Cookie Ltd. certificate

What caught my attention was that the download was called Skype_Setup.exe. This might look like an official Skype download, but it is not. If it was an official download, it should have been digitally signed by Skype Software Sarl. Here’s how the authentic Skype looks like when you double click on it. Notice that the “Verified publisher” says “Skype Software Sarl”.
Skype Software Sarl publisher

The problem with the Funnel Connector (Fried Cookie Ltd.) file is that it is detected by some of the anti-viruses. Here are some of the detection names: Application.Win32.FriedCookie.CIRK, Win32.Application.InstallCore.DI and InstallCore (fs).

Funnel Connector Fried Cookie Ltd anti-virus report

Did you also find an Funnel Connector (Fried Cookie Ltd.)? Do you remember the download link? Please post it in the comments below and I’ll upload it to VirusTotal to see if that one is also detected.

Thanks for reading.

Platform Connector (Fried Cookie Ltd.) – 12% Anti-Virus Detection – InstallCore

Hello readers! If you’ve been following my recent posts here on the FreeFixer blog, you know that I’ve been looking at files that have a valid digital signature and bundle various types of potentially unwanted programs and programs that works as a downloader. A few days ago I found another publisher named Platform Connector (Fried Cookie Ltd.).

Platform Connector Fried Cookie Ltd. certificate

Information about a digital signature and the certificate can be found under the Digital Signature tab. The screenshot shows the Platform Connector (Fried Cookie Ltd.) certificate. From the certificate info we can see that Platform Connector (Fried Cookie Ltd.) appears to be located in Tel Aviv in Israel.

So, why am I writing about the Platform Connector (Fried Cookie Ltd.) file? Check out what the anti-viruses report about the file:

Avira detects installer_jdownloader_English.exe as Adware/InstallCore.734264, ESET-NOD32 reports a variant of Win32/InstallCore.WX potentially unwanted, K7GW reports Trojan ( 004b61851 ) and VIPRE reports InstallCore (fs) are a few of the detection names for installer_jdownloader_English.exe.

Platform Connector fried cookie anti-virus report

Did you also find a Platform Connector (Fried Cookie Ltd.) file? Do you remember where you downloaded it?

Thank you for reading.

Best Standard (Fried Cookie Ltd.) – 9% Detection Rate – InstallCore

Welcome! If you are a regular here on the FreeFixer blog you know that I’ve been looking on the certificates used to sign files that bundled various types of unwanted software. Today I found another certificate, used by a publisher called Best Standard (Fried Cookie Ltd.).

Best Standard Certificate

To get more details on the publisher, you can view the embedded certificate by right-clicking on the file, and looking under the Digital Signatures tab. According to the certificate we can see that Best Standard (Fried Cookie Ltd.) seems to be located in Tel Aviv, Israel and that the certificate is issued by GlobalSign CodeSigning CA – G2.

What caught my attention was that the download was called Skype_Setup.exe. This might look like an official Skype download, but it is not. If it was an official download, it would have been signed by Skype Software Sarl. Here’s how the authentic Skype looks like when you double click on it. Notice that the “Verified publisher” says “Skype Software Sarl”.
Skype Software Sarl publisher

When I uploaded the Best Standard (Fried Cookie Ltd.) file to VirusTotal, it came up with a 9% detection rate. The file is detected as Application.Win32.FriedCookie.CIRK by Comodo, a variant of Win32/InstallCore.WX potentially unwanted by ESET-NOD32 and InstallCore (fs) by VIPRE.

Best Standard Fried Cookie Ltd

Did you also find a file digitally signed by Best Standard (Fried Cookie Ltd.)? Where did you find it and are the anti-virus programs detecting it? Please share in the comments below.

Thank you for reading.

Max Source (After Download Ltd.) – 9% Detection Rate – InstallCore

Hello readers! Just a short post on a publisher called Max Source (After Download Ltd.) that I found while downloading “FileZilla” from SourceForge. Big thanks to Peter for letting me know about this download.

This is how Max Source (After Download Ltd.) appears when running the file:

Max Source After Download  Ltd in the User Account Control dialog

To get more details on the publisher, you can view the certificate by right-clicking on the file, and looking under the Digital Signatures tab. According to the certificate we can see that Max Source (After Download Ltd.) is located in Tel Aviv, Israel and that the certificate is issued by GlobalSign CodeSigning CA – G2.

Max Source After Download  Ltd certificate

It turns out that SourceForge.net has been into bundling for quite some time. Here’s a blog post dated July 2013 which describes the DevShare bundling program.

The reason I’m writing this blog post is that the Max Source (After Download Ltd.) file is detected by some of the anti-malware software at VirusTotal. Avira detects FileZilla_3.10.1.1_win32-setup.exe as Adware/InstallCore.765232, DrWeb classifies it as Trojan.InstallCore.52, ESET-NOD32 reports a variant of Win32/InstallCore.WI potentially unwanted, K7AntiVirus calls it Trojan ( 004b52261 ) and K7GW calls it Trojan ( 004b52261 ).

Max Source anti-virus report

Did you also find a file digitally signed by Max Source (After Download Ltd.)? Where did you find it and are the anti-virus programs detecting it? Please share in the comments below.

Here’s how the download screen looks like for FileZilla at sourceforge.net. It hints that something will be bundled by saying “provide you some options during the installation process…”

sourceforge downloader

Thanks for reading.

Avitzur Efrati Management Initiatives Ltd – 4% Anti-Virus Detection Rate – InstallCore

Hello! Hope you are doing well. I’m working from the local library today. Was looking for some downloads to play around with last night and found one, signed by Avitzur Efrati Management Initiatives Ltd. The file is named mozilla_firefox.exe.

Avitzur Efrati  Management Initiatives Ltd

The Avitzur Efrati Management Initiatives Ltd certificate shows that the publisher is located in Petah Tikva, Israel.

The problem here is that if mozilla_firefox.exe really was an installer file for Mozilla Firefox, it would have been signed by Mozilla Corporation and not by some unknown company. Here’s how the authentic Mozilla Firefox looks like when you double click on it. Notice that the “Verified publisher” says “Mozilla Corporation”.
Mozilla Corporation publisher

When I uploaded the file to VirusTotal – as I usually do when I find something that looks suspicious – Only 4% of the scanners detected the file. The file is detected as Generic.C83 by AVG and a variant of Win32/InstallCore.WT potentially unwanted by ESET-NOD32.

Did you also find a Avitzur Efrati Management Initiatives Ltd file? What kind of download was it?

Thank you for reading.

Best Service (Fried Cookie Ltd) – Detected by 9% of the Anti-Virus Scanners

Hello readers! Bugging you with another of those Fried Cookie posts 🙂 This publisher is called Best Service (Fried Cookie Ltd). The suspicious file is was named FlvPlayerSetup.exe.

Best Service Fried Cookie Ltd certificate

You can see the Best Service (Fried Cookie Ltd) certificate by looking under the Digital Signature tab on the file’s properties. According to the certificate, Best Service (Fried Cookie Ltd) is located in Tel Aviv in Israel.

So, why did I put up this blog post? Well, the thing is that the Best Service (Fried Cookie Ltd) file is detected by some of the anti-malware scanners, according to VirusTotal. Avira classifies FlvPlayerSetup.exe as ADWARE/InstallCore.Gen, ESET-NOD32 reports a variant of Win32/InstallCore.WI potentially unwanted and VIPRE classifies it as InstallCore.b (fs).

Best Service virustotal

Did you also find a Best Service (Fried Cookie Ltd) file?

Thank you for reading.

Leading Funnel (Fried Cookie Ltd.) – 16% Detection Rate – InstallCore

Heya! I was playing around and testing some downloads last night and found a file digitally signed by Leading Funnel (Fried Cookie Ltd.).

Leading Funnel Fried Cookie Ltd certificate

To view more information about the certificate you can right-click on the file, then choose Properties and then select the Digital Signatures tab. According to the certificate we can see that Leading Funnel (Fried Cookie Ltd.) appears to be located in Tel Aviv and that the certificate is issued by GlobalSign CodeSigning CA – G2.

When I uploaded the file to VirusTotal – as I usually do when I find something that looks suspicious – 16% of the antivirus scanners detected the file. The file is detected as Application.Win32.FriedCookie.CIRK by Comodo, Trojan.InstallCore.53 by DrWeb, a variant of Win32/InstallCore.VM potentially unwanted by ESET-NOD32 and InstallCore (fs) by VIPRE.

Leading Funnel Fried Cookie Ltd. virustotal

Did you also find a Leading Funnel (Fried Cookie Ltd.) file? Do you remember where you downloaded it?

Thanks for reading.

World Setup (New Media Holdings Ltd.) – 11% Detection Rate – InstallCore

Hello readers! Just wanted to give you heads-up on suspicious file I found right now. The file is named ChromeSetup.exe and digitally signed by World Setup (New Media Holdings Ltd.).

It’s possible to view additional information about the certificate by right-clicking on the file, choosing properties and then clicking on the Digital Signatures tab. According to the certificate we can see that World Setup (New Media Holdings Ltd.) appears to be located in Tel Aviv, Israel and that the certificate is issued by GlobalSign CodeSigning CA – G2.

World Setup (New Media Holdings Ltd.) certificate

The problem is that ChromeSetup.exe is not an official Google Chrome download. If it was, it would be digitally signed by Google Inc.. Here’s how the authentic Google Chrome looks like when you double click on it. Notice that the “Verified publisher” says “Google Inc”.
Chrome Google Inc publisher

After uploading the World Setup (New Media Holdings Ltd.) file – ChromeSetup.exe – to VirusTotal, it was clear that it’s probably better to stay away from file than running it. The detection rate was 11% and some of the detection names were: ADWARE/InstallCore.Gen, Application.Win32.InstallCore.DR and InstallCore (fs).

Since you probably came here after finding a download that was digitally signed by World Setup (New Media Holdings Ltd.), please share what kind of download it was and if it was detected by the antimalware scanners at VirusTotal.

Thanks for reading.

Setup Delivery (Fried Cookie Ltd.) – 21% Detection Rate – InstallCore

Hi there! Just wanted to give you the heads up on a publisher called Setup Delivery (Fried Cookie Ltd.). By looking at the certificate we can see that Setup Delivery (Fried Cookie Ltd.) appears to be located in Tel Aviv in Israel.

Setup Delivery (Fried Cookie Ltd.) certificate

So, why did I put up this blog post? Well, the thing is that the Setup Delivery (Fried Cookie Ltd.) file is detected by many of the scanners, according to VirusTotal. Avira names installer_jdownloader_English.exe as ADWARE/InstallCore.Gen7, Comodo classifies it as Application.Win32.FriedCookie.CIRK, Sophos detects it as Install Core and VIPRE classifies it as InstallCore (fs)

Setup Delivery virustotal

Did you also find an Setup Delivery (Fried Cookie Ltd.)? Do you remember the download link? Please post it in the comments below and I’ll upload it to VirusTotal to see if that one is also detected.

Thank you for reading.