Antivirus XP fake antivirus application
Wednesday, August 27th, 2008Antivirus XP fake antivirus application. Stay away from following domains.


| File wmcodec_update.exe received on 08.27.2008 14:28:46 (CET) | |||
| Antivirus | Version | Last Update | Result |
| AhnLab-V3 | 2008.8.27.1 | 2008.08.27 | - |
| AntiVir | 7.8.1.23 | 2008.08.27 | - |
| Authentium | 5.1.0.4 | 2008.08.27 | - |
| Avast | 4.8.1195.0 | 2008.08.26 | - |
| AVG | 8.0.0.161 | 2008.08.27 | Downloader.Zlob_r.AP |
| BitDefender | 7.2 | 2008.08.27 | Trojan.Zlob.CQW |
| CAT-QuickHeal | 9.50 | 2008.08.26 | Backdoor.Small.fax |
| ClamAV | 0.93.1 | 2008.08.27 | - |
| DrWeb | 4.44.0.09170 | 2008.08.27 | - |
| eSafe | 7.0.17.0 | 2008.08.26 | - |
| eTrust-Vet | 31.6.6050 | 2008.08.26 | - |
| Ewido | 4.0 | 2008.08.27 | - |
| F-Prot | 4.4.4.56 | 2008.08.27 | - |
| F-Secure | 7.60.13501.0 | 2008.08.27 | - |
| Fortinet | 3.14.0.0 | 2008.08.26 | - |
| GData | 19 | 2008.08.27 | Backdoor.Win32.Frauder.ba |
| Ikarus | T3.1.1.34.0 | 2008.08.27 | Virus.Trojan.Win32.BHO.egw |
| K7AntiVirus | 7.10.428 | 2008.08.25 | - |
| Kaspersky | 7.0.0.125 | 2008.08.27 | Backdoor.Win32.Frauder.ba |
| McAfee | 5370 | 2008.08.26 | - |
| Microsoft | 1.3807 | 2008.08.25 | Trojan:Win32/Zlob.AR |
| NOD32v2 | 3391 | 2008.08.27 | a variant of Win32/Kryptik.E |
| Norman | 5.80.02 | None.. | Malware.DJFR |
| Panda | 9.0.0.4 | 2008.08.26 | - |
| PCTools | 4.4.2.0 | 2008.08.26 | - |
| Prevx1 | V2 | 2008.08.27 | Malware Dropper |
| Rising | 20.59.21.00 | 2008.08.27 | - |
| Sophos | 4.32.0 | 2008.08.27 | - |
| Sunbelt | 3.1.1582.1 | 2008.08.26 | - |
| Symantec | 10 | 2008.08.27 | Trojan.Zlob |
| TheHacker | 6.3.0.6.060 | 2008.08.23 | Backdoor/Small.foh |
| TrendMicro | 8.700.0.1004 | 2008.08.27 | - |
| VBA32 | 3.12.8.4 | 2008.08.26 | - |
| ViRobot | 2008.8.27.1352 | 2008.08.27 | - |
| VirusBuster | 4.5.11.0 | 2008.08.26 | - |
| Webwasher-Gateway | 6.6.2 | 2008.08.27 | - |
| Additional information | |||
| File size: 308776 bytes | |||
| MD5…: 54d20d0df83c6fe073573deb28f5b638 | |||
| SHA1..: 62e209ecbf63985f8b0f72e1432cb18e2a34e4b8 | |||
| SHA256: 3bc80959012f8aeebb7723b53dc3617be60e714b1c5c85ad178a057ece3e53a2 | |||
| SHA512: 84c34da128a3c64d3295400dfab1762d13132c6e4ef5d848e984e04bd7558a1b 57495332e7b7629e36252788c2defa1e19f7d3bd34b87fa05158cd47f999ef38 |
|||
| PEiD..: - | |||
| TrID..: File type identification Win32 Executable MS Visual C++ (generic) (65.2%) Win32 Executable Generic (14.7%) Win32 Dynamic Link Library (generic) (13.1%) Generic Win/DOS Executable (3.4%) DOS Executable Generic (3.4%) |
|||
| Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=D1239C3528E5526DB649048B5DF64C009681CBDE | |||

| File young_girl_getting_fucked_by_big_ received on 08.27.2008 15:00:36 (CET) | |||
| Antivirus | Version | Last Update | Result |
| AhnLab-V3 | 2008.8.27.1 | 2008.08.27 | - |
| AntiVir | 7.8.1.23 | 2008.08.27 | - |
| Authentium | 5.1.0.4 | 2008.08.27 | - |
| Avast | 4.8.1195.0 | 2008.08.26 | - |
| AVG | 8.0.0.161 | 2008.08.27 | Downloader.FraudLoad.N |
| BitDefender | 7.2 | 2008.08.27 | - |
| CAT-QuickHeal | 9.50 | 2008.08.26 | (Suspicious) - DNAScan |
| ClamAV | 0.93.1 | 2008.08.27 | - |
| DrWeb | 4.44.0.09170 | 2008.08.27 | Trojan.Packed.619 |
| eSafe | 7.0.17.0 | 2008.08.26 | Suspicious File |
| eTrust-Vet | 31.6.6052 | 2008.08.27 | - |
| Ewido | 4.0 | 2008.08.27 | - |
| F-Prot | 4.4.4.56 | 2008.08.27 | - |
| F-Secure | 7.60.13501.0 | 2008.08.27 | - |
| Fortinet | 3.14.0.0 | 2008.08.26 | - |
| GData | 19 | 2008.08.27 | - |
| Ikarus | T3.1.1.34.0 | 2008.08.27 | - |
| K7AntiVirus | 7.10.428 | 2008.08.25 | - |
| Kaspersky | 7.0.0.125 | 2008.08.27 | - |
| McAfee | 5370 | 2008.08.26 | Downloader-ASH.gen.b |
| Microsoft | 1.3807 | 2008.08.25 | - |
| NOD32v2 | 3392 | 2008.08.27 | a variant of Win32/Kryptik.E |
| Norman | 5.80.02 | 2008.08.26 | - |
| Panda | 9.0.0.4 | 2008.08.26 | - |
| PCTools | 4.4.2.0 | 2008.08.26 | - |
| Prevx1 | V2 | 2008.08.27 | Malicious Software |
| Rising | 20.59.21.00 | 2008.08.27 | - |
| Sophos | 4.32.0 | 2008.08.27 | - |
| Sunbelt | 3.1.1582.1 | 2008.08.26 | - |
| Symantec | 10 | 2008.08.27 | - |
| TheHacker | 6.3.0.6.060 | 2008.08.23 | - |
| TrendMicro | 8.700.0.1004 | 2008.08.27 | - |
| VBA32 | 3.12.8.4 | 2008.08.26 | - |
| ViRobot | 2008.8.27.1352 | 2008.08.27 | - |
| VirusBuster | 4.5.11.0 | 2008.08.26 | - |
| Webwasher-Gateway | 6.6.2 | 2008.08.27 | - |
| Additional information | |||
| File size: 203776 bytes | |||
| MD5…: 2ee9946c99e529b98ee0c58ca28e6b8e | |||
| SHA1..: 14d1935a0d6f496dcf7f89cfc84f38ff97c2caff | |||
| SHA256: fa62eb0bbc17809e588bd6422fca36b68b17f6b41bffd42d78e4548b53ea4485 | |||
| SHA512: 8033cbfe03b9a7853bf01162f68059ef48120c2c9968d72a976129b81347c19f 66b3e4efeb7f2853f2a80657c131a224e921c6b8f36450e37cbe06d4082d14c0 |
|||
| PEiD..: - | |||
| TrID..: File type identification Win32 Executable Generic (38.4%) Win32 Dynamic Link Library (generic) (34.2%) Clipper DOS Executable (9.1%) Generic Win/DOS Executable (9.0%) DOS Executable Generic (9.0%) |
|||
| Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=A8F4150A00A906FD1C41038A8291FA005723E3DC | |||

Host: celebstape.com
IP: 85.255.117.218
Whois of IP 85.255.117.218 distributing fake antivirus Antivirus XP:
netname: UkrTeleGroup
descr: UkrTeleGroup Ltd.
country: UA
organisation: ORG-UL25-RIPE
org-name: UkrTeleGroup Ltd.
org-type: LIR
address: UkrTeleGroup Ltd.
Mechnikova 58/5
65029 Odessa
Ukraine
phone: +380487311011
fax-no: +380487502499
person: Andrew Sotov
address: Mechnikova 58/5 65029 Odessa
abuse-mailbox: abuse@ukrtelegroup.com.ua
Other sites of IP 85.255.117.218 distributing fake antivirus Antivirus XP:
1. Bestfunnyvids.com
2. Celebs69.com
3. Celebsnofake.com
4. Celebstape.com
5. Celebsvidsonline.com
6. Codecservice1.com
7. Codecservice6.com
8. Favoredtube.com
9. Freevidshardcore.com
10. Myeasytube.com
11. Newfunnyvideo.com
12. Sexlookupworld.com
13. Siteresults1.com
14. Starfeed1.com
15. Starfeed2.com
16. Topsearchresults6.com
17. Yourfavoritetube.com
18. Topresults1.com
Host: www.teenhardmovs.com
IP: 195.42.103.32
Whois of IP 195.42.103.32 distributing fake antivirus Antivirus XP:
descr: Todayhost Limited
country: NL
org: ORG-TH5-RIPE
admin-c: AD4931-RIPE
tech-c: AD4931-RIPE
status: ASSIGNED PI
mnt-by: RIPE-NCC-HM-PI-MNT
mnt-by: TODAYHOST-MNT
mnt-lower: RIPE-NCC-HM-PI-MNT
mnt-routes: TODAYHOST-MNT
mnt-domains: TODAYHOST-MNT
source: RIPE # Filteredorganisation: ORG-TH5-RIPE
org-name: Todayhost Limited
org-type: OTHER
address: 164 Victoria Street
address: London
address: SW1E 5LB
address: GB
phone: +44 2076300600
fax-no: +44 8702889352
abuse-mailbox: abuse@2dayhost.com
Other sites of IP 195.42.103.32 distributing fake antivirus Antivirus XP:
1. Davoyeur.com
2. Edenteen.com
3. Euroartstudio.com
4. Jaobdsm.com
5. Jaobondage.com
6. Jaofemdom.com
7. Jaofetish.com
8. Jaomature.com
9. Jaomatures.com
10. Jaomoms.com
11. Jaomomvideos.com
12. Jaomovies.com
13. Jaonetwork.com
14. Jaoporn.com
15. Jaosex.com
16. Jaostrapon.com
17. Jaotgp.com
18. Teendaporn.com
19. Teendasex.com
20. Teenhardmovs.com
21. Teensboss.com
22. Yamilf.com
Host: avxp08.net
IP: 200.63.45.19
Whois of IP 200.63.45.19 distributing fake antivirus Antivirus XP:
status: reallocated
owner: Ricardo Carreras
ownerid: HN-RICA-LACNIC
responsible: Honduras Web
address: P.O.Box: 1142 La Ceiba, #37 street., 1142, 37
address: 00000 - Tegucigalpa - TE
country: HN
phone: +504 9815-3645 []
owner-c: RIC9
tech-c: RIC9
abuse-c: RIC9
created: 20080630
changed: 20080630
inetnum-up: 200.63.40/21nic-hdl: RIC9
person: Ricardo Carreras
e-mail: hn-rica@ONLINEABUSECENTER.COM
Other sites of IP 200.63.45.19 distributing fake antivirus Antivirus XP:
1. Antivirusxp-08.net
2. Online-security-guide.com
Host: stat.avxp08.net
IP: 77.244.220.134
Whois of IP 77.244.220.134 distributing fake antivirus Antivirus XP:
netname: PRIMENET1
descr: Allocation for our customer PrimeNet
country: RU
admin-c: RZT1-RIPE
tech-c: RZT1-RIPE
status: ASSIGNED PA
mnt-by: RZT-MNT
mnt-lower: RZT-MNT
mnt-routes: RZT-MNT
source: RIPE # Filteredperson: Network Admins RZT-SERVICE
address: 191011 Saint-Petersburg, Russia
address: Lomonosova sq. 1
phone: +78123142643
e-mail: rztncc@sysadmins.spb.ru
Other sites of IP 77.244.220.134 distributing fake antivirus Antivirus XP:
1. Antivirus-xp-08.com
2. Antivirusxp-08.com
3. Antivirusxp-2008.com
4. Antivirusxp08.net
5. Antivirxp08.com
6. Av-xp-08.com
7. Av-xp-2008.com
8. Avxp-08.com
9. Avxp-2008.com
10. Avxp08.com
11. Avxp2008.com
12. Winifixer.net
13. Winifixer.org
14. Winqfixer.com
Host: secure.eglobalbilling.com
IP: 216.195.56.31
Whois of IP 216.195.56.31 selling fake antivirus Antivirus XP:
OrgName: APS Telecom
OrgID: APSTE
Address: 8130 SW BEAVERTON-HILLSDALE HWY
City: PORTLAND
StateProv: OR
PostalCode: 97225
Country: USNetRange: 216.195.32.0 - 216.195.63.255
CIDR: 216.195.32.0/19
NetName: APS-EPSI
NetHandle: NET-216-195-32-0-1
Parent: NET-216-0-0-0-0
NetType: Direct Allocation
NameServer: NS1.3FN.NET
NameServer: NS2.3FN.NET
Comment: send abuse issues to abuse@3fn.net, send network
Comment: issue to noc@3fn.net
RegDate: 2003-11-05
Updated: 2004-09-17RTechHandle: NSW-ARIN
RTechName: Swen, Nash
RTechPhone: +1-800-539-8209
RTechEmail: noc@apxtelecom.com
Other sites of IP 216.195.56.31 selling fake antivirus Antivirus XP:
1. Adult-billing.com
2. Billhlp.com
3. Billingcenteronline.com
4. Billinghost.net
5. Billingintegrator.com
6. Billingmill.com
7. Billingserviceonline.com
8. Billingsquad.net
9. Billingsvc.com
10. Billinternet.com
11. Billsvc.com
12. Customerhlp.com
13. Ebillingcenter.com
14. Eglobalbilling.com
15. Extrabilling.com
16. Fantazybill.com
17. Legalbillingsystems.com
18. Mainbillingcenter.com
19. Orderhlp.com
20. Paymentbit.com
21. Paymentbit.net
22. Paymentforge.com
23. Safepaymentsonline.com
24. Software-payment.com
25. Spankyhosting.com
26. Support-wizard.com
27. Truebillingservices.com
28. Ultimatepayment.com
29. Supporthlp.com





