Antivirus 2009 rogue antivirus application
November 19, 2008 | Malware, Rogues
Antivirus 2009 a rogue antivirus application. To remove that rogue application viruses and antispyware use Kaspersky antivirus - http://cleanthe.net/how-to-remove-virus/


| File v-codec.123.exe received on 11.19.2008 16:23:57 (CET) | |||
| Antivirus | Version | Last Update | Result |
| AhnLab-V3 | 2008.11.18.2 | 2008.11.19 | - |
| AntiVir | 7.9.0.34 | 2008.11.19 | - |
| Authentium | 5.1.0.4 | 2008.11.18 | - |
| Avast | 4.8.1281.0 | 2008.11.18 | - |
| AVG | 8.0.0.199 | 2008.11.19 | - |
| BitDefender | 7.2 | 2008.11.19 | - |
| CAT-QuickHeal | 10.00 | 2008.11.19 | - |
| ClamAV | 0.94.1 | 2008.11.19 | - |
| DrWeb | 4.44.0.09170 | 2008.11.19 | - |
| eSafe | 7.0.17.0 | 2008.11.18 | Suspicious File |
| eTrust-Vet | 31.6.6216 | 2008.11.19 | - |
| Ewido | 4.0 | 2008.11.19 | - |
| F-Prot | 4.4.4.56 | 2008.11.18 | - |
| F-Secure | 8.0.14332.0 | 2008.11.19 | - |
| Fortinet | 3.117.0.0 | 2008.11.19 | - |
| GData | 19 | 2008.11.19 | - |
| Ikarus | T3.1.1.45.0 | 2008.11.19 | Trojan-Downloader.Win32.CodecPack |
| K7AntiVirus | 7.10.527 | 2008.11.18 | - |
| Kaspersky | 7.0.0.125 | 2008.11.19 | - |
| McAfee | 5438 | 2008.11.18 | - |
| Microsoft | 1.4104 | 2008.11.19 | TrojanDownloader:Win32/Renos.BAH |
| NOD32 | 3624 | 2008.11.19 | Win32/TrojanDownloader.Zlob.CVG |
| Norman | 5.80.02 | 2008.11.19 | - |
| Panda | 9.0.0.4 | 2008.11.19 | - |
| PCTools | 4.4.2.0 | 2008.11.19 | - |
| Prevx1 | V2 | 2008.11.19 | Malware Dropper |
| Rising | 21.04.22.00 | 2008.11.19 | - |
| SecureWeb-Gateway | 6.7.6 | 2008.11.19 | - |
| Sophos | 4.35.0 | 2008.11.19 | Troj/Dloadr-CAG |
| Sunbelt | 3.1.1801.2 | 2008.11.14 | - |
| Symantec | 10 | 2008.11.19 | Downloader |
| TheHacker | 6.3.1.1.158 | 2008.11.19 | - |
| TrendMicro | 8.700.0.1004 | 2008.11.19 | Possible_DLDER |
| VBA32 | 3.12.8.9 | 2008.11.19 | - |
| ViRobot | 2008.11.18.1474 | 2008.11.18 | - |
| VirusBuster | 4.5.11.0 | 2008.11.18 | - |
| Additional information | |||
| File size: 50176 bytes | |||
| MD5…: eec2d22e39d75355539f7eb7ff384fc2 | |||
| SHA1..: 0ba883d406a51f5194c1ea5df2f8d78f02a30342 | |||
| SHA256: b396ab2fc5128eb3643b0e483bcefe146c2fc855e3658eba7ab2b83df1b81860 | |||
| SHA512: a3f42f426d7df0688984b57c89953cafab9432fc91793328c0385bbb2b471e3a 4897f4fc4efa6045e9181df30d74f40d34bcbf23d6e7a4ca0e4ca01aa2386270 |
|||
| PEiD..: - | |||
| TrID..: File type identification Win32 Executable Generic (42.3%) Win32 Dynamic Link Library (generic) (37.6%) Generic Win/DOS Executable (9.9%) DOS Executable Generic (9.9%) Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%) |
|||
| Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=45B34567006772C7C4750054B66A1E00137572E3 | |||


| File A9installertest_77100102.exe received on 11.19.2008 16:24:06 (CET) | |||
| Antivirus | Version | Last Update | Result |
| AhnLab-V3 | 2008.11.18.2 | 2008.11.19 | - |
| AntiVir | 7.9.0.34 | 2008.11.19 | - |
| Authentium | 5.1.0.4 | 2008.11.18 | - |
| Avast | 4.8.1281.0 | 2008.11.18 | - |
| AVG | 8.0.0.199 | 2008.11.19 | - |
| BitDefender | 7.2 | 2008.11.19 | - |
| CAT-QuickHeal | 10.00 | 2008.11.19 | - |
| ClamAV | 0.94.1 | 2008.11.19 | - |
| DrWeb | 4.44.0.09170 | 2008.11.19 | - |
| eSafe | 7.0.17.0 | 2008.11.18 | - |
| eTrust-Vet | 31.6.6216 | 2008.11.19 | - |
| Ewido | 4.0 | 2008.11.19 | - |
| F-Prot | 4.4.4.56 | 2008.11.18 | - |
| F-Secure | 8.0.14332.0 | 2008.11.19 | - |
| Fortinet | 3.117.0.0 | 2008.11.19 | - |
| GData | 19 | 2008.11.19 | - |
| Ikarus | T3.1.1.45.0 | 2008.11.19 | - |
| K7AntiVirus | 7.10.527 | 2008.11.18 | - |
| Kaspersky | 7.0.0.125 | 2008.11.19 | - |
| McAfee | 5438 | 2008.11.18 | - |
| Microsoft | 1.4104 | 2008.11.19 | Trojan:Win32/FakeXPA |
| NOD32 | 3624 | 2008.11.19 | - |
| Norman | 5.80.02 | 2008.11.19 | - |
| Panda | 9.0.0.4 | 2008.11.19 | - |
| PCTools | 4.4.2.0 | 2008.11.19 | - |
| Prevx1 | V2 | 2008.11.19 | - |
| Rising | 21.04.22.00 | 2008.11.19 | - |
| SecureWeb-Gateway | 6.7.6 | 2008.11.19 | - |
| Sophos | 4.35.0 | 2008.11.19 | - |
| Sunbelt | 3.1.1801.2 | 2008.11.14 | - |
| Symantec | 10 | 2008.11.19 | - |
| TheHacker | 6.3.1.1.158 | 2008.11.19 | - |
| TrendMicro | 8.700.0.1004 | 2008.11.19 | - |
| VBA32 | 3.12.8.9 | 2008.11.19 | - |
| ViRobot | 2008.11.18.1474 | 2008.11.18 | - |
| VirusBuster | 4.5.11.0 | 2008.11.18 | - |
| Additional information | |||
| File size: 163840 bytes | |||
| MD5…: b58b7c0fca632601b7b6f22faf0c73ac | |||
| SHA1..: ea50267f8ccdb033d3b1a2c060cc238f084e23fa | |||
| SHA256: a67e4fe36e60fbe3db906591fbede08bae239c1afb55ebc715879e57d621debf | |||
| SHA512: e4f4a17190f92e9371ce6aa2e74bf4dc016c30071e4a061ff6dbac116a41e15d bd64b95d9b4545b4b85ff07259a77158df2970c67d595db304cf368b0bfedc55 |
|||
| PEiD..: - | |||
| TrID..: File type identification Win32 Executable Generic (42.3%) Win32 Dynamic Link Library (generic) (37.6%) Generic Win/DOS Executable (9.9%) DOS Executable Generic (9.9%) VXD Driver (0.1%) |
|||
| PEInfo: PE Structure information | |||
Host: imp-porntube.net
IP: 64.27.28.224
Whois:
OrgName: Hollywood Interactive, Inc.
OrgID: HLWD
Address: 600 W. 7th Street, Ste. 360
City: Los Angeles
StateProv: CA
PostalCode: 90017
Country: USNetRange: 64.27.0.0 - 64.27.31.255
CIDR: 64.27.0.0/19
NetName: HOLLYWOOD-INTERACTIVE
NetHandle: NET-64-27-0-0-1
Parent: NET-64-0-0-0-0
NetType: Direct Allocation
NameServer: NS1.CALPOP.COM
NameServer: NS2.CALPOP.COM
Comment: ADDRESSES WITHIN THIS BLOCK ARE NON-PORTABLE
RegDate: 2000-01-10
Updated: 2004-09-13RNOCHandle: CNO4-ARIN
RNOCName: CalPOP Network Operations
RNOCPhone: +1-213-627-1937
RNOCEmail: noc@calpop.com
Other sites:
1. Celebs4you-online2008.com
2. I-av-sscan2009.com
3. Imp-porntube.net
Host: antivirusdefense.com
IP: 69.10.44.207
Whois:
OrgName: Interserver, Inc
OrgID: INTER-83
Address: 110 Meadowlands Pkwy
Address: 1st Floor
City: Secaucus
StateProv: NJ
PostalCode: 07094
Country: US
Host: www.win-security-scanner.org
IP: 115.126.5.92
Whois:
OrgName: Asia Pacific Network Information Centre
OrgID: APNIC
Address: PO Box 2131
City: Milton
StateProv: QLD
PostalCode: 4064
Country: AU
Other sites:
1. Spy-protector.org
2. Win-security-scanner.org
3. Spy-protector.biz
Host: powerfulvirusremover2008.com
IP: 77.245.61.80
Whois:
descr: Webair Internet Development company, Inc
country: NL
org: ORG-RII1-RIPE
admin-c: RIIS1-RIPE
tech-c: RIIS1-RIPE
status: ALLOCATED PA
mnt-by: RIPE-NCC-HM-MNT
mnt-lower: GLOBALAXS-MNT
mnt-lower: WEBAIRINC-MTL
mnt-domains: MNT-RECURRING
mnt-routes: MNT-RECURRING
source: RIPE # Filteredorganisation: ORG-RII1-RIPE
org-name: Webair Internet Development company, Inc
org-type: LIR
address: Recurring International Inc
Sagi Brody
REDBUS INTERHOUSE (NETHERLANDS) B V GYROSCOOPWEG 2E
AB 1042 AMSTERDAM
Netherlands
phone: +31 20 4804400
fax-no: +15169385100
Other sites:
1. Mysecureexpertcleaner.com
2. Pcvirusremover2008.com
3. Powerfulvirusremover2008.com
4. Prosecureexpertcleaner.com
5. Prosecureexpertcleanerpro.com
6. Registrydoctor2008-online.com
7. Registrydoctor2008-pro.com
8. Registrydoctor2008-scan.com
9. Registrydoctor2008.com
10. Registrydoctorpro2008.com
11. Secureexpertcleaner.com
12. Securefileshred.com
13. Securefileshredder.com
14. Securefileshredder2009.com
15. Securefilesshred.com
16. Securefilesshredder.com
17. Strongvirusremover2008.com
18. Supersecurefileshredder.com
19. Topregistrydoctor2008.com
20. Virusremover2008flash.com
21. Virusremover2008plus.com
22. Winsecureexpertcleaner.com
23. Yoursecureexpertcleaner.com
Host: official-antivirus2009.com
IP: 84.243.196.136
Whois:
org-name: PortNAP Internet Services
org-type: OTHER
address: Beverwaardseweg 232
address: 3077GD Rotterdam
address: The Netherlands
phone: +31.612928606
mnt-ref: GFX-MNT
mnt-by: GFX-MNT
source: RIPE # Filteredrole: GrafiX NOC
org: ORG-GIB1-RIPE
address: GrafiX Internet B.V.
address: Stationsplein 20
address: 2907 MJ Capelle aan den IJssel
phone: +31 10 2640210
fax-no: +31 10 2640211
Host: softwarebillingservice.com
IP: 63.219.177.214
Whois of softwarebillingservice.com
Registration Service Provided By: ERDOMAIN.COM
Contact: +49.3036741521
Website: http://www.erdomain.comDomain Name: SOFTWAREBILLINGSERVICE.COM
Registrant:
N/A
Viktor Temchenko (temchenkoviktor@googlemail.com)
Pr. Geroev Tryda
Kharkov
Kharkiv Oblast,01001
UA
Tel. +380.936328480Creation Date: 03-Nov-2008
Expiration Date: 03-Nov-2009
Whois of 63.219.177.214
OrgName: Beyond The Network America, Inc.
OrgID: BNA-42
Address: 450 Springpark PL
Address: Suite 100
City: Herdon
StateProv: VA
PostalCode: 20170
Country: US

Antivirus 2009 from Pandora software













































