Archive for August 13th, 2008

Internet Antivirus fake antivirus software

Wednesday, August 13th, 2008

Internet Antivirus is fake antivirus software. DO NOT download any software from domain(s) of Internet Antivirus!

Internet Antivirus

Internet Antivirus

 

File IAInstall.exe received on 08.13.2008 14:56:25 (CET)
Antivirus Version Last Update Result
AhnLab-V3 2008.8.13.0 2008.08.13 -
AntiVir 7.8.1.19 2008.08.13 TR/Crypt.XPACK.Gen
Authentium 5.1.0.4 2008.08.12 -
Avast 4.8.1195.0 2008.08.12 -
AVG 8.0.0.161 2008.08.13 -
BitDefender 7.2 2008.08.13 GenPack:Trojan.FakeAV.AI
CAT-QuickHeal 9.50 2008.08.12 (Suspicious) - DNAScan
ClamAV 0.93.1 2008.08.13 -
DrWeb 4.44.0.09170 2008.08.13 -
eSafe 7.0.17.0 2008.08.12 Suspicious File
eTrust-Vet 31.6.6030 2008.08.13 -
Ewido 4.0 2008.08.13 -
F-Prot 4.4.4.56 2008.08.12 -
F-Secure 7.60.13501.0 2008.08.13 -
Fortinet 3.14.0.0 2008.08.13 -
GData 2.0.7306.1023 2008.08.13 -
Ikarus T3.1.1.34.0 2008.08.13 -
K7AntiVirus 7.10.412 2008.08.12 -
Kaspersky 7.0.0.125 2008.08.13 -
McAfee 5359 2008.08.12 -
Microsoft 1.3807 2008.08.13 -
NOD32v2 3352 2008.08.13 -
Norman 5.80.02 2008.08.13 -
Panda 9.0.0.4 2008.08.13 -
PCTools 4.4.2.0 2008.08.13 -
Prevx1 V2 2008.08.13 -
Rising 20.57.22.00 2008.08.13 -
Sophos 4.32.0 2008.08.13 -
Sunbelt 3.1.1542.1 2008.08.13 -
Symantec 10 2008.08.13 -
TheHacker 6.3.0.3.046 2008.08.13 -
TrendMicro 8.700.0.1004 2008.08.13 -
VBA32 3.12.8.3 2008.08.13 -
ViRobot 2008.8.13.1335 2008.08.13 -
VirusBuster 4.5.11.0 2008.08.12 -
Webwasher-Gateway 6.6.2 2008.08.13 Trojan.Crypt.XPACK.Gen
 
Additional information
File size: 41984 bytes
MD5…: 6a9260432417c475a78d7ef022860aae
SHA1..: 16ce3db6a6533076f41401e910d67d2c77c2238a
SHA256: ec67330696a288dbbe4e1210090db1648606a54fb7f0556f23f177eb0e267379
SHA512: 07faf645f8705ecaaa8df90b93c99a3f686770ab6f5114d7be4860a7cd23c271
3837d38089d991e1a08625cd223952c72d1851637d49b675b949f65e84e71cd6
PEiD..: -

 

File InternetAntivirus.exe received on 08.13.2008 16:00:32 (CET)
Antivirus Version Last Update Result
AhnLab-V3 2008.8.13.0 2008.08.13 -
AntiVir 7.8.1.19 2008.08.13 -
Authentium 5.1.0.4 2008.08.13 -
Avast 4.8.1195.0 2008.08.12 -
AVG 8.0.0.161 2008.08.13 -
BitDefender 7.2 2008.08.13 BehavesLike:Win32.ExplorerHijack
CAT-QuickHeal 9.50 2008.08.13 -
ClamAV 0.93.1 2008.08.13 -
DrWeb 4.44.0.09170 2008.08.13 -
eSafe 7.0.17.0 2008.08.12 -
eTrust-Vet 31.6.6030 2008.08.13 -
Ewido 4.0 2008.08.13 -
F-Prot 4.4.4.56 2008.08.13 -
F-Secure 7.60.13501.0 2008.08.13 -
Fortinet 3.14.0.0 2008.08.13 -
GData 2.0.7306.1023 2008.08.13 -
Ikarus T3.1.1.34.0 2008.08.13 -
K7AntiVirus 7.10.413 2008.08.13 -
Kaspersky 7.0.0.125 2008.08.13 Heur.Invader
McAfee 5359 2008.08.12 -
Microsoft 1.3807 2008.08.13 -
NOD32v2 3352 2008.08.13 -
Norman 5.80.02 2008.08.13 -
Panda 9.0.0.4 2008.08.13 -
PCTools 4.4.2.0 2008.08.13 -
Prevx1 V2 2008.08.13 -
Rising 20.57.22.00 2008.08.13 -
Sophos 4.32.0 2008.08.13 -
Sunbelt 3.1.1542.1 2008.08.13 -
Symantec 10 2008.08.13 InternetAntivirus
TheHacker 6.3.0.3.046 2008.08.13 -
TrendMicro 8.700.0.1004 2008.08.13 -
VBA32 3.12.8.3 2008.08.13 -
ViRobot 2008.8.13.1335 2008.08.13 -
VirusBuster 4.5.11.0 2008.08.12 -
Webwasher-Gateway 6.6.2 2008.08.13 -
 
Additional information
File size: 2356372 bytes
MD5…: cad4cdd3d9b903efc453fdbcb8f63ee6
SHA1..: 6f9a6448b0193532cc216c5a8b0fcc425362ee14
SHA256: e16a9a305fa67623b6bcea10c65b0ae7c92163c7344939904e9bb2fac4c4eada
SHA512: d01e5817cdca3fc13da7984abcc836558ad40e295f5385731138f98b51383996
474864a8fa81a3eff1a71d24e618a1f0ef210982241836e3cb7a5589298aa3ba
PEiD..: -

Host: ia-scanner.com
IP: 216.32.69.162

Whois:

OrgName:    Savvis
OrgID:      SAVVI-3
Address:    3300 Regency Parkway
City:       Cary
StateProv:  NC
PostalCode: 27511
Country:    US
OrgAbuseHandle: ABUSE11-ARIN
OrgAbuseName:   Abuse
OrgAbusePhone:  +1-877-393-7878
OrgAbuseEmail:  abuse@savvis.com

Host: internet-Antivirus.com
IP: 216.32.69.165

Whois of IP 216.32.69.165 distributing fake antivirus Internet Antivirus:

OrgName:    Savvis
OrgID:      SAVVI-3
Address:    3300 Regency Parkway
City:       Cary
StateProv:  NC
PostalCode: 27511
Country:    US
OrgAbuseHandle: ABUSE11-ARIN
OrgAbuseName:   Abuse
OrgAbusePhone:  +1-877-393-7878
OrgAbuseEmail:  abuse@savvis.com

Other sites on IP 216.32.69.165 distributing fake antivirus Internet Antivirus: :

1.  Ia-license.com 
2.  Ia-payment.com 
3.  Ia-support.com 
4.  Internet-antivirus.com 
5.  Ia-payment-now.com 

Internet Antivirus

Internet Antivirus

Internet Antivirus

Host: secure.software-payment.com
IP: 216.195.56.160

Whois:

OrgID:      APSTE
Address:    8130 SW BEAVERTON-HILLSDALE HWY
City:       PORTLAND
StateProv:  OR
PostalCode: 97225
Country:    US

NetRange:   216.195.32.0 - 216.195.63.255
CIDR:       216.195.32.0/19
NetName:    APS-EPSI
NetHandle:  NET-216-195-32-0-1
Parent:     NET-216-0-0-0-0
NetType:    Direct Allocation
NameServer: NS1.3FN.NET
NameServer: NS2.3FN.NET
Comment:    send abuse issues to abuse@3fn.net , send network

RTechHandle: NSW-ARIN
RTechName:   Swen, Nash
RTechPhone:  +1-800-539-8209
RTechEmail : noc@apxnoctelecom.com

Page 1 of 11