Archive for August 27th, 2008

Antivirus XP fake antivirus application

Wednesday, August 27th, 2008

Antivirus XP fake antivirus application. Stay away from following domains.

Antivirus XP

Antivirus XP

File wmcodec_update.exe received on 08.27.2008 14:28:46 (CET)
Antivirus Version Last Update Result
AhnLab-V3 2008.8.27.1 2008.08.27 -
AntiVir 7.8.1.23 2008.08.27 -
Authentium 5.1.0.4 2008.08.27 -
Avast 4.8.1195.0 2008.08.26 -
AVG 8.0.0.161 2008.08.27 Downloader.Zlob_r.AP
BitDefender 7.2 2008.08.27 Trojan.Zlob.CQW
CAT-QuickHeal 9.50 2008.08.26 Backdoor.Small.fax
ClamAV 0.93.1 2008.08.27 -
DrWeb 4.44.0.09170 2008.08.27 -
eSafe 7.0.17.0 2008.08.26 -
eTrust-Vet 31.6.6050 2008.08.26 -
Ewido 4.0 2008.08.27 -
F-Prot 4.4.4.56 2008.08.27 -
F-Secure 7.60.13501.0 2008.08.27 -
Fortinet 3.14.0.0 2008.08.26 -
GData 19 2008.08.27 Backdoor.Win32.Frauder.ba
Ikarus T3.1.1.34.0 2008.08.27 Virus.Trojan.Win32.BHO.egw
K7AntiVirus 7.10.428 2008.08.25 -
Kaspersky 7.0.0.125 2008.08.27 Backdoor.Win32.Frauder.ba
McAfee 5370 2008.08.26 -
Microsoft 1.3807 2008.08.25 Trojan:Win32/Zlob.AR
NOD32v2 3391 2008.08.27 a variant of Win32/Kryptik.E
Norman 5.80.02 None.. Malware.DJFR
Panda 9.0.0.4 2008.08.26 -
PCTools 4.4.2.0 2008.08.26 -
Prevx1 V2 2008.08.27 Malware Dropper
Rising 20.59.21.00 2008.08.27 -
Sophos 4.32.0 2008.08.27 -
Sunbelt 3.1.1582.1 2008.08.26 -
Symantec 10 2008.08.27 Trojan.Zlob
TheHacker 6.3.0.6.060 2008.08.23 Backdoor/Small.foh
TrendMicro 8.700.0.1004 2008.08.27 -
VBA32 3.12.8.4 2008.08.26 -
ViRobot 2008.8.27.1352 2008.08.27 -
VirusBuster 4.5.11.0 2008.08.26 -
Webwasher-Gateway 6.6.2 2008.08.27 -
 
Additional information
File size: 308776 bytes
MD5…: 54d20d0df83c6fe073573deb28f5b638
SHA1..: 62e209ecbf63985f8b0f72e1432cb18e2a34e4b8
SHA256: 3bc80959012f8aeebb7723b53dc3617be60e714b1c5c85ad178a057ece3e53a2
SHA512: 84c34da128a3c64d3295400dfab1762d13132c6e4ef5d848e984e04bd7558a1b
57495332e7b7629e36252788c2defa1e19f7d3bd34b87fa05158cd47f999ef38
PEiD..: -
TrID..: File type identification
Win32 Executable MS Visual C++ (generic) (65.2%)
Win32 Executable Generic (14.7%)
Win32 Dynamic Link Library (generic) (13.1%)
Generic Win/DOS Executable (3.4%)
DOS Executable Generic (3.4%)
 
Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=D1239C3528E5526DB649048B5DF64C009681CBDE

Antivirus XP

File young_girl_getting_fucked_by_big_ received on 08.27.2008 15:00:36 (CET)
Antivirus Version Last Update Result
AhnLab-V3 2008.8.27.1 2008.08.27 -
AntiVir 7.8.1.23 2008.08.27 -
Authentium 5.1.0.4 2008.08.27 -
Avast 4.8.1195.0 2008.08.26 -
AVG 8.0.0.161 2008.08.27 Downloader.FraudLoad.N
BitDefender 7.2 2008.08.27 -
CAT-QuickHeal 9.50 2008.08.26 (Suspicious) - DNAScan
ClamAV 0.93.1 2008.08.27 -
DrWeb 4.44.0.09170 2008.08.27 Trojan.Packed.619
eSafe 7.0.17.0 2008.08.26 Suspicious File
eTrust-Vet 31.6.6052 2008.08.27 -
Ewido 4.0 2008.08.27 -
F-Prot 4.4.4.56 2008.08.27 -
F-Secure 7.60.13501.0 2008.08.27 -
Fortinet 3.14.0.0 2008.08.26 -
GData 19 2008.08.27 -
Ikarus T3.1.1.34.0 2008.08.27 -
K7AntiVirus 7.10.428 2008.08.25 -
Kaspersky 7.0.0.125 2008.08.27 -
McAfee 5370 2008.08.26 Downloader-ASH.gen.b
Microsoft 1.3807 2008.08.25 -
NOD32v2 3392 2008.08.27 a variant of Win32/Kryptik.E
Norman 5.80.02 2008.08.26 -
Panda 9.0.0.4 2008.08.26 -
PCTools 4.4.2.0 2008.08.26 -
Prevx1 V2 2008.08.27 Malicious Software
Rising 20.59.21.00 2008.08.27 -
Sophos 4.32.0 2008.08.27 -
Sunbelt 3.1.1582.1 2008.08.26 -
Symantec 10 2008.08.27 -
TheHacker 6.3.0.6.060 2008.08.23 -
TrendMicro 8.700.0.1004 2008.08.27 -
VBA32 3.12.8.4 2008.08.26 -
ViRobot 2008.8.27.1352 2008.08.27 -
VirusBuster 4.5.11.0 2008.08.26 -
Webwasher-Gateway 6.6.2 2008.08.27 -
 
Additional information
File size: 203776 bytes
MD5…: 2ee9946c99e529b98ee0c58ca28e6b8e
SHA1..: 14d1935a0d6f496dcf7f89cfc84f38ff97c2caff
SHA256: fa62eb0bbc17809e588bd6422fca36b68b17f6b41bffd42d78e4548b53ea4485
SHA512: 8033cbfe03b9a7853bf01162f68059ef48120c2c9968d72a976129b81347c19f
66b3e4efeb7f2853f2a80657c131a224e921c6b8f36450e37cbe06d4082d14c0
PEiD..: -
TrID..: File type identification
Win32 Executable Generic (38.4%)
Win32 Dynamic Link Library (generic) (34.2%)
Clipper DOS Executable (9.1%)
Generic Win/DOS Executable (9.0%)
DOS Executable Generic (9.0%)
 
Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=A8F4150A00A906FD1C41038A8291FA005723E3DC

Antivirus XP

Host: celebstape.com
IP:  85.255.117.218

Whois of IP 85.255.117.218 distributing fake antivirus Antivirus XP:

netname:        UkrTeleGroup
descr:          UkrTeleGroup Ltd.
country:        UA
organisation:   ORG-UL25-RIPE
org-name:       UkrTeleGroup Ltd.
org-type:       LIR
address:        UkrTeleGroup Ltd.
                Mechnikova 58/5
                65029 Odessa
                Ukraine
phone:          +380487311011
fax-no:         +380487502499
person:         Andrew Sotov
address:        Mechnikova 58/5 65029 Odessa
abuse-mailbox:  abuse@ukrtelegroup.com.ua

Other sites of IP 85.255.117.218 distributing fake antivirus Antivirus XP:

1.  Bestfunnyvids.com 
2.  Celebs69.com 
3.  Celebsnofake.com 
4.  Celebstape.com 
5.  Celebsvidsonline.com 
6.  Codecservice1.com 
7.  Codecservice6.com 
8.  Favoredtube.com 
9.  Freevidshardcore.com 
10.  Myeasytube.com 
11.  Newfunnyvideo.com 
12.  Sexlookupworld.com 
13.  Siteresults1.com 
14.  Starfeed1.com 
15.  Starfeed2.com 
16.  Topsearchresults6.com 
17.  Yourfavoritetube.com 
18.  Topresults1.com 

 
Host: www.teenhardmovs.com
IP: 195.42.103.32

Whois of IP 195.42.103.32 distributing fake antivirus Antivirus XP:

descr:          Todayhost Limited
country:        NL
org:            ORG-TH5-RIPE
admin-c:        AD4931-RIPE
tech-c:         AD4931-RIPE
status:         ASSIGNED PI
mnt-by:         RIPE-NCC-HM-PI-MNT
mnt-by:         TODAYHOST-MNT
mnt-lower:      RIPE-NCC-HM-PI-MNT
mnt-routes:     TODAYHOST-MNT
mnt-domains:    TODAYHOST-MNT
source:         RIPE # Filtered

organisation:   ORG-TH5-RIPE
org-name:       Todayhost Limited
org-type:       OTHER
address:        164 Victoria Street
address:        London
address:        SW1E 5LB
address:        GB
phone:          +44 2076300600
fax-no:         +44 8702889352
abuse-mailbox:  abuse@2dayhost.com

Other sites of IP 195.42.103.32 distributing fake antivirus Antivirus XP:

1.  Davoyeur.com 
2.  Edenteen.com 
3.  Euroartstudio.com 
4.  Jaobdsm.com 
5.  Jaobondage.com 
6.  Jaofemdom.com 
7.  Jaofetish.com 
8.  Jaomature.com 
9.  Jaomatures.com 
10.  Jaomoms.com 
11.  Jaomomvideos.com 
12.  Jaomovies.com 
13.  Jaonetwork.com 
14.  Jaoporn.com 
15.  Jaosex.com 
16.  Jaostrapon.com 
17.  Jaotgp.com 
18.  Teendaporn.com 
19.  Teendasex.com 
20.  Teenhardmovs.com 
21.  Teensboss.com 
22.  Yamilf.com 

 
Host: avxp08.net
IP: 200.63.45.19

Whois of IP 200.63.45.19 distributing fake antivirus Antivirus XP:

status:      reallocated
owner:       Ricardo Carreras
ownerid:     HN-RICA-LACNIC
responsible: Honduras Web
address:     P.O.Box: 1142 La Ceiba, #37 street., 1142, 37
address:     00000 - Tegucigalpa - TE
country:     HN
phone:       +504  9815-3645 []
owner-c:     RIC9
tech-c:      RIC9
abuse-c:     RIC9
created:     20080630
changed:     20080630
inetnum-up:  200.63.40/21

nic-hdl:     RIC9
person:      Ricardo Carreras
e-mail:      hn-rica@ONLINEABUSECENTER.COM

Other sites of IP 200.63.45.19 distributing fake antivirus Antivirus XP:

1.  Antivirusxp-08.net 
2.  Online-security-guide.com 

Host: stat.avxp08.net
IP: 77.244.220.134

Whois of IP 77.244.220.134 distributing fake antivirus Antivirus XP:

netname:        PRIMENET1
descr:          Allocation for our customer PrimeNet
country:        RU
admin-c:        RZT1-RIPE
tech-c:         RZT1-RIPE
status:         ASSIGNED PA
mnt-by:         RZT-MNT
mnt-lower:      RZT-MNT
mnt-routes:     RZT-MNT
source:         RIPE # Filtered

person:         Network Admins  RZT-SERVICE
address:        191011 Saint-Petersburg, Russia
address:        Lomonosova sq. 1
phone:          +78123142643
e-mail:         rztncc@sysadmins.spb.ru

Other sites of IP 77.244.220.134 distributing fake antivirus Antivirus XP:

1.  Antivirus-xp-08.com 
2.  Antivirusxp-08.com 
3.  Antivirusxp-2008.com 
4.  Antivirusxp08.net 
5.  Antivirxp08.com 
6.  Av-xp-08.com 
7.  Av-xp-2008.com 
8.  Avxp-08.com 
9.  Avxp-2008.com 
10.  Avxp08.com 
11.  Avxp2008.com 
12.  Winifixer.net 
13.  Winifixer.org 
14.  Winqfixer.com 

Host: secure.eglobalbilling.com
IP: 216.195.56.31

Whois of IP 216.195.56.31 selling fake antivirus Antivirus XP:

OrgName:    APS Telecom
OrgID:      APSTE
Address:    8130 SW BEAVERTON-HILLSDALE HWY
City:       PORTLAND
StateProv:  OR
PostalCode: 97225
Country:    US

NetRange:   216.195.32.0 - 216.195.63.255
CIDR:       216.195.32.0/19
NetName:    APS-EPSI
NetHandle:  NET-216-195-32-0-1
Parent:     NET-216-0-0-0-0
NetType:    Direct Allocation
NameServer: NS1.3FN.NET
NameServer: NS2.3FN.NET
Comment:    send abuse issues to abuse@3fn.net, send network
Comment:    issue to noc@3fn.net
RegDate:    2003-11-05
Updated:    2004-09-17

RTechHandle: NSW-ARIN
RTechName:   Swen, Nash
RTechPhone:  +1-800-539-8209
RTechEmail:  noc@apxtelecom.com

Other sites of IP 216.195.56.31 selling fake antivirus Antivirus XP:

1.  Adult-billing.com 
2.  Billhlp.com 
3.  Billingcenteronline.com 
4.  Billinghost.net 
5.  Billingintegrator.com 
6.  Billingmill.com 
7.  Billingserviceonline.com 
8.  Billingsquad.net 
9.  Billingsvc.com 
10.  Billinternet.com 
11.  Billsvc.com 
12.  Customerhlp.com 
13.  Ebillingcenter.com 
14.  Eglobalbilling.com 
15.  Extrabilling.com 
16.  Fantazybill.com 
17.  Legalbillingsystems.com 
18.  Mainbillingcenter.com 
19.  Orderhlp.com 
20.  Paymentbit.com 
21.  Paymentbit.net 
22.  Paymentforge.com 
23.  Safepaymentsonline.com 
24.  Software-payment.com 
25.  Spankyhosting.com 
26.  Support-wizard.com 
27.  Truebillingservices.com 
28.  Ultimatepayment.com 
29.  Supporthlp.com 

Antivirus XP

IE Antivirus fake antivirus application

Wednesday, August 27th, 2008

IE Antivirus is a fake antivirus application. Stay away from following domains providing IE Antivrus.

IE Antivirus

File c-setup.exe received on 08.27.2008 13:53:26 (CET)
Antivirus Version Last Update Result
AhnLab-V3 2008.8.27.1 2008.08.27 -
AntiVir 7.8.1.23 2008.08.27 TR/BHO.ggd.1
Authentium 5.1.0.4 2008.08.27 W32/Adware-RegBHO-based.1!Maximus
Avast 4.8.1195.0 2008.08.26 -
AVG 8.0.0.161 2008.08.27 Downloader.Zlob.ABBG
BitDefender 7.2 2008.08.27 -
CAT-QuickHeal 9.50 2008.08.26 TrojanDownloader.Agent.acuy
ClamAV 0.93.1 2008.08.27 -
DrWeb 4.44.0.09170 2008.08.27 Trojan.DownLoad.4175
eSafe 7.0.17.0 2008.08.26 -
eTrust-Vet 31.6.6050 2008.08.26 -
Ewido 4.0 2008.08.27 -
F-Prot 4.4.4.56 2008.08.27 W32/Adware-RegBHO-based.1!Maximus
Fortinet 3.14.0.0 2008.08.26 -
GData 19 2008.08.27 Trojan-Downloader.Win32.Agent.acuy
Ikarus T3.1.1.34.0 2008.08.27 Trojan-Dropper.Win32.Delf.aho
K7AntiVirus 7.10.428 2008.08.25 -
Kaspersky 7.0.0.125 2008.08.27 Trojan-Downloader.Win32.Agent.acuy
McAfee 5370 2008.08.26 -
Microsoft 1.3807 2008.08.25 TrojanDownloader:Win32/Renos.DG
NOD32v2 3391 2008.08.27 Win32/Adware.IeDefender.NGX
Norman 5.80.02 2008.08.26 W32/Malware.DOZM
Panda 9.0.0.4 2008.08.26 Suspicious file
PCTools 4.4.2.0 2008.08.26 -
Prevx1 V2 2008.08.27 Cloaked Malware
Rising 20.59.21.00 2008.08.27 Trojan.Win32.Vapsup.euf
Sophos 4.32.0 2008.08.27 Mal/FakeVir-E
Sunbelt 3.1.1582.1 2008.08.26 -
Symantec 10 2008.08.27 -
TheHacker 6.3.0.6.060 2008.08.23 -
TrendMicro 8.700.0.1004 2008.08.27 TROJ_FAKEAVAL.Z
VBA32 3.12.8.4 2008.08.26 -
ViRobot 2008.8.27.1352 2008.08.27 Trojan.Win32.Downloader.73229
VirusBuster 4.5.11.0 2008.08.26 -
Webwasher-Gateway 6.6.2 2008.08.27 Trojan.BHO.ggd.1
Additional information
File size: 73223 bytes
MD5…: 2d4c052a9ee633e2010a9233458a63b9
SHA1..: c13476196e68c0c9f2726ed8b7a62193ed56eee1
SHA256: b76f61520f8daa7965eb19d0d268377b1a63dd226a8f6033c4ea2b386302a4d1
SHA512: 73f12d791e0cc02b1345c6ab46206b5972545888bda0c460cbd3eb7539ba38b0
7cb5904a0051c0de56206ffda4108d2841691f2a32ebee64ae32ea3bda04c6ef
PEiD..: -
TrID..: File type identification
Win32 Executable Borland Delphi 6 (92.2%)
Win32 Executable Generic (2.9%)
Win32 Dynamic Link Library (generic) (2.6%)
Win16/32 Executable Delphi generic (0.7%)
Generic Win/DOS Executable (0.7%)
Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=C315D09207C06EF71E400141329DB1009C98C68F
packers (F-Prot): embedded
packers (Authentium): embedded

IE Antivirus

File ie-av.exe received on 08.27.2008 14:01:53 (CET)
Antivirus Version Last Update Result
AhnLab-V3 2008.8.27.1 2008.08.27 -
AntiVir 7.8.1.23 2008.08.27 ADSPY/AdSpy.Gen
Authentium 5.1.0.4 2008.08.27 -
Avast 4.8.1195.0 2008.08.26 -
AVG 8.0.0.161 2008.08.27 Generic3.LTE
BitDefender 7.2 2008.08.27 -
CAT-QuickHeal 9.50 2008.08.26 -
ClamAV 0.93.1 2008.08.27 -
DrWeb 4.44.0.09170 2008.08.27 Trojan.Fakealert.origin
eSafe 7.0.17.0 2008.08.26 -
eTrust-Vet 31.6.6050 2008.08.26 -
Ewido 4.0 2008.08.27 -
F-Prot 4.4.4.56 2008.08.27 -
F-Secure 7.60.13501.0 2008.08.27 -
Fortinet 3.14.0.0 2008.08.26 -
GData 19 2008.08.27 -
Ikarus T3.1.1.34.0 2008.08.27 AdWare.AdSpy
K7AntiVirus 7.10.428 2008.08.25 -
Kaspersky 7.0.0.125 2008.08.27 -
McAfee 5370 2008.08.26 -
Microsoft 1.3807 2008.08.25 Trojan:Win32/Delflob.I
NOD32v2 3391 2008.08.27 probably a variant of Win32/Adware.IeDefender
Norman 5.80.02 2008.08.26 -
Panda 9.0.0.4 2008.08.26 Adware/IEAntivirus
PCTools 4.4.2.0 2008.08.26 -
Prevx1 V2 2008.08.27 Malicious Software
Rising 20.59.21.00 2008.08.27 -
Sophos 4.32.0 2008.08.27 -
Sunbelt 3.1.1582.1 2008.08.26 -
Symantec 10 2008.08.27 -
TheHacker 6.3.0.6.060 2008.08.23 -
TrendMicro 8.700.0.1004 2008.08.27 TROJ_FAKEAV.CO
VBA32 3.12.8.4 2008.08.26 -
ViRobot 2008.8.27.1352 2008.08.27 -
VirusBuster 4.5.11.0 2008.08.26 -
Webwasher-Gateway 6.6.2 2008.08.27 Ad-Spyware.AdSpy.Gen
Additional information
File size: 1030702 bytes
MD5…: 61f11e6594f2cd6d44a788c2994a127e
SHA1..: 87ed01632689bfe8752c536e2a0e3bd01af10780
SHA256: bacb513eae54755c9599c1c955efa06bc8ffe8292ac3d8e78913be56a8a120d3
SHA512: 2909bd598806a8e4295d5c03a214b19f696965631307855a63c8b53dbfe32fcc
17f8a77fed4214ee433b4d7ff1156f3822c380dc23e0e2a1221f6eb3e5d45825
PEiD..: -
TrID..: File type identification
Win32 Executable MS Visual C++ (generic) (65.2%)
Win32 Executable Generic (14.7%)
Win32 Dynamic Link Library (generic) (13.1%)
Generic Win/DOS Executable (3.4%)
DOS Executable Generic (3.4%)
PEInfo: PE Structure information
ThreatExpert info: http://www.threatexpert.com/report.aspx?md5=61f11e6594f2cd6d44a788c2994a127e
Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=5829EF4D2E000463BA7C0F25256D5F00C777D033

IE Antivirus

Host: cometoseemyshow.com
IP: 91.203.92.97

Whois of IP 91.203.92.97 distributing fake antivirus IE Antivirus:

descr:          ISP UATelecom ukrainian national holding LLC
country:        EU
organisation:   ORG-TG39-RIPE
org-name:       UATELECOM LLC
org-type:       OTHER
address:        Ukraine
address:        Voznesensk
address:        Lenina 52
phone:          +380963801321
phone:          +380963801326
fax-no:         +380963801326
abuse-mailbox:  abuse@uatelecom.com.ua

Other sites of IP 91.203.92.97 distributing fake antivirus IE Antivirus:

1.  Cometoseemyshow.com
2.  Ie-antivirus-order.com
3.  Mustseethatvid.com
4.  Onlythebestvid.com
5.  Mysoftwarefreezone.com
6.  Myveryprivatevid.com
7.  Thefreemusicmp3.com
8.  Secure-order-box.com

Host: mydownloadbackup.com
IP: 58.65.238.34
Whois of IP 58.65.238.34 distributing fake antivirus IE Antivirus:

netname:      HOSTFRESH
descr:        HostFresh
descr:        Internet Service Provider
country:      HK
admin-c:      PL466-AP
tech-c:       PL466-AP
status:       ALLOCATED PORTABLE
mnt-by:       APNIC-HM
mnt-lower:    MAINT-HK-HOSTFRESH
mnt-routes:   MAINT-HK-HOSTFRESH
remarks:      Please send Spam & Abuse report to
remarks:      abuse@hostfresh.com

Other sites of IP 58.65.238.34 distributing fake antivirus IE Antivirus:

1.  Free-viruscan.com
2.  Getdefender2009.com
3.  Hotvid44.com
4.  Ie-anti-virus.com
5.  Ie-antivirus.com
6.  Ieantivirus.com
7.  Malwarebell.com

Host: thevid11.com
IP: 91.203.92.99

Whois:

descr:          ISP UATelecom ukrainian national holding LLC
country:        EU
organisation:   ORG-TG39-RIPE
org-name:       UATELECOM LLC
org-type:       OTHER
address:        Ukraine
address:        Voznesensk
address:        Lenina 52
phone:          +380963801321
phone:          +380963801326
fax-no:         +380963801326
abuse-mailbox:  abuse@uatelecom.com.ua

Other sites:

1.  Thevid11.com
2.  Thevid22.com

Host: ie-anti-virus.com
IP: 91.203.92.97

Whois of IP 91.203.92.97 distributing fake antivirus IE Antivirus:

descr:          ISP UATelecom ukrainian national holding LLC
country:        EU
organisation:   ORG-TG39-RIPE
org-name:       UATELECOM LLC
org-type:       OTHER
address:        Ukraine
address:        Voznesensk
address:        Lenina 52
phone:          +380963801321
phone:          +380963801326
fax-no:         +380963801326
abuse-mailbox:  abuse@uatelecom.com.ua

Other sites of IP 91.203.92.97 distributing fake antivirus IE Antivirus:

1.  Cometoseemyshow.com
2.  Ie-antivirus-order.com
3.  Mustseethatvid.com
4.  Onlythebestvid.com
5.  Mysoftwarefreezone.com
6.  Myveryprivatevid.com
7.  Thefreemusicmp3.com
8.  Secure-order-box.com

Host: windowsdefender2009.com
IP: 77.244.220.141

Whois:

descr:          Allocation for our customer PrimeNet
country:        RU
person:         Network Admins  RZT-SERVICE
address:        191011 Saint-Petersburg, Russia
address:        Lomonosova sq. 1
phone:          +78123142643
e-mail:         rztncc@sysadmins.spb.ru

Host: ie-antivirus-order.com
IP: 91.203.92.97

Whois of IP 91.203.92.97 selling fake antivirus IE Antivirus:

descr:          ISP UATelecom ukrainian national holding LLC
country:        EU
organisation:   ORG-TG39-RIPE
org-name:       UATELECOM LLC
org-type:       OTHER
address:        Ukraine
address:        Voznesensk
address:        Lenina 52
phone:          +380963801321
phone:          +380963801326
fax-no:         +380963801326
abuse-mailbox:  abuse@uatelecom.com.ua

IE Antivirus

Page 1 of 11