Antivrus XP 2008 rogue antivirus software

August 30, 2008 | Malware, Rogues

Antivrus XP 2008 rogue antivirus software. Stay away from Antivirus XP 2008 domains and products!

Antivirus XP 2008

 

File HDVideoCodec_ver1.5000.0.exe received on 08.30.2008 14:57:09 (CET)
Antivirus Version Last Update Result
AhnLab-V3 2008.8.29.0 2008.08.29 -
AntiVir 7.8.1.23 2008.08.29 TR/Dldr.Zlob.Gen
Authentium 5.1.0.4 2008.08.30 -
Avast 4.8.1195.0 2008.08.30 -
AVG 8.0.0.161 2008.08.29 -
BitDefender 7.2 2008.08.30 -
CAT-QuickHeal 9.50 2008.08.29 -
ClamAV 0.93.1 2008.08.30 -
DrWeb 4.44.0.09170 2008.08.30 -
eSafe 7.0.17.0 2008.08.28 -
eTrust-Vet 31.6.6057 2008.08.29 -
Ewido 4.0 2008.08.30 -
F-Prot 4.4.4.56 2008.08.29 -
F-Secure 7.60.13501.0 2008.08.30 Suspicious:W32/Malware!Gemini
Fortinet 3.14.0.0 2008.08.30 -
GData 19 2008.08.30 -
Ikarus T3.1.1.34.0 2008.08.30 -
K7AntiVirus 7.10.432 2008.08.29 -
Kaspersky 7.0.0.125 2008.08.30 -
McAfee 5373 2008.08.29 -
Microsoft 1.3807 2008.08.25 -
NOD32v2 3401 2008.08.30 -
Norman 5.80.02 2008.08.29 -
Panda 9.0.0.4 2008.08.30 -
PCTools 4.4.2.0 2008.08.30 -
Prevx1 V2 2008.08.30 -
Rising 20.59.51.00 2008.08.30 -
Sophos 4.33.0 2008.08.30 -
Sunbelt 3.1.1592.1 2008.08.29 -
Symantec 10 2008.08.30 -
TheHacker 6.3.0.6.068 2008.08.30 -
TrendMicro 8.700.0.1004 2008.08.29 -
VBA32 3.12.8.4 2008.08.30 -
ViRobot 2008.8.30.1357 2008.08.30 -
VirusBuster 4.5.11.0 2008.08.29 -
Webwasher-Gateway 6.6.2 2008.08.29 Trojan.Dldr.Zlob.Gen
 
Additional information
File size: 73744 bytes
MD5…: b80faf46733fbfbe1d159da5d8f42ced
SHA1..: e9233af85800bedd8f5cbdae7cb46d5389455f39
SHA256: 6700703bb1348b4a938d22db9e355e8383e116739172389b811dd71b74b41e7c
SHA512: 5157cabad81628b8f532600141a85ee1cdbc95931503625794008773a22765c4
5071d3b8c3417219519c12fe321a5026759d5aead52a4b5a645cfc318c9afbd5
PEiD..: -
TrID..: File type identification
Win32 Executable MS Visual C++ (generic) (65.2%)
Win32 Executable Generic (14.7%)
Win32 Dynamic Link Library (generic) (13.1%)
Generic Win/DOS Executable (3.4%)
DOS Executable Generic (3.4%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0×403ce0
timedatestamp…..: 0×48b935aa (Sat Aug 30 11:57:30 2008)
machinetype…….: 0×14c (I386)

( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0×1000 0×9c1e 0xa000 6.55 426a8a8c28538887181747a80f185d44
.rdata 0xb000 0×40a4 0×5000 4.60 0df3cca6910ced4c5d481372ce4177cf
.data 0×10000 0×1858 0×1000 2.36 4a0eaf8806525a0b8f7014f49641c452
.rsrc 0×12000 0xb0 0×1000 3.06 3d3a7a1efbcbff194582c5f5e1ecfd75

( 2 imports )
> KERNEL32.dll: HeapAlloc, GetProcessHeap, LoadLibraryA, GetProcAddress, SetLastError, FreeLibrary, GetVersionExA, HeapFree, GetLastError, GetCurrentProcess, lstrlenA, lstrcatA, GetCurrentThread, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, GetCPInfo, InterlockedIncrement, InterlockedDecrement, GetACP, GetOEMCP, IsValidCodePage, GetModuleHandleA, TlsGetValue, TlsSetValue, GetCurrentThreadId, LCMapStringA, WideCharToMultiByte, MultiByteToWideChar, LCMapStringW, GetStringTypeA, GetStringTypeW, LeaveCriticalSection, EnterCriticalSection, ExitProcess, Sleep, GetLocaleInfoA, InitializeCriticalSection, WriteFile, GetStdHandle, GetModuleFileNameA, VirtualFree, VirtualAlloc, HeapReAlloc, RtlUnwind, RaiseException
> USER32.dll: wsprintfA

( 0 exports )

Antivirus XP 2008

File scan.exe received on 08.30.2008 14:59:04 (CET)
Antivirus Version Last Update Result
AhnLab-V3 2008.8.29.0 2008.08.29 -
AntiVir 7.8.1.23 2008.08.29 -
Authentium 5.1.0.4 2008.08.30 -
Avast 4.8.1195.0 2008.08.30 -
AVG 8.0.0.161 2008.08.29 -
BitDefender 7.2 2008.08.30 -
CAT-QuickHeal 9.50 2008.08.29 (Suspicious) - DNAScan
ClamAV 0.93.1 2008.08.30 -
DrWeb 4.44.0.09170 2008.08.30 -
eSafe 7.0.17.0 2008.08.28 Suspicious File
eTrust-Vet 31.6.6057 2008.08.29 -
Ewido 4.0 2008.08.30 -
F-Prot 4.4.4.56 2008.08.29 -
F-Secure 7.60.13501.0 2008.08.30 -
Fortinet 3.14.0.0 2008.08.30 -
GData 19 2008.08.30 -
Ikarus T3.1.1.34.0 2008.08.30 -
K7AntiVirus 7.10.432 2008.08.29 -
Kaspersky 7.0.0.125 2008.08.30 -
McAfee 5373 2008.08.29 -
Microsoft 1.3807 2008.08.25 -
NOD32v2 3401 2008.08.30 -
Norman 5.80.02 2008.08.29 W32/Tibs.gen226
Panda 9.0.0.4 2008.08.30 -
PCTools 4.4.2.0 2008.08.30 -
Prevx1 V2 2008.08.30 -
Rising 20.59.51.00 2008.08.30 -
Sophos 4.33.0 2008.08.30 -
Sunbelt 3.1.1592.1 2008.08.30 -
Symantec 10 2008.08.30 -
TheHacker 6.3.0.6.068 2008.08.30 -
TrendMicro 8.700.0.1004 2008.08.29 -
VBA32 3.12.8.4 2008.08.30 -
ViRobot 2008.8.30.1357 2008.08.30 -
VirusBuster 4.5.11.0 2008.08.29 -
Webwasher-Gateway 6.6.2 2008.08.29 -
 
Additional information
File size: 50688 bytes
MD5…: 6b32a74fbc1f2b9bd5a9c86bb52427c5
SHA1..: 2803dc43b49ce31c3de54041b1b0cc42adef359c
SHA256: 4251140a5fd688fcd5cb395a93a7ee6efc2c01c346f3f97d53415643a88901ac
SHA512: c6843d1cb69d7be1bfa7508035b5df0ba9076945caaabceaba8f25ff0977a68f
23ddfbc1e50e4c25984f403266f66222c8b061b6331c318de60ac239ea0b2fc4
PEiD..: -
TrID..: File type identification
Win32 Executable Generic (38.4%)
Win32 Dynamic Link Library (generic) (34.2%)
Clipper DOS Executable (9.1%)
Generic Win/DOS Executable (9.0%)
DOS Executable Generic (9.0%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0×402258
timedatestamp…..: 0×48a5bf02 (Fri Aug 15 17:38:10 2008)
machinetype…….: 0×14c (I386)

( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0×1000 0xae44 0×7800 7.99 4e6ad154cd9fc2335c847ee81b7f2bbe
.rdata 0xc000 0×3200 0×1800 7.96 a1f8cd5bfc1d48e52b4f7b3cb6b9a519
.data 0×10000 0xbea 0×200 7.57 2e1f36802fe10ad3a411ab12b550cfb3
.rsrc 0×11000 0xf000 0×3000 6.62 aaae96e43c99de829c0a0e495f4dc23c

( 4 imports )
> gdi32.dll: SetRelAbs, StretchBlt, SetICMMode, ResetDCW, UpdateColors, SaveDC, TextOutW, SetDIBColorTable
> wsock32.dll: bind, WSAStartup, listen
> kernel32.dll: CreatePipe, TerminateProcess, VirtualProtect
> shell32.dll: SHAppBarMessage, StrRChrIA, StrStrIA

( 0 exports )

Antivirus XP 2008

Host: directcubeone.net
IP: 78.157.143.217

Whois of IP 78.157.143.217 distibuting rogue antivirus Antivirurus XP 2008 :

1.  Hqsextube08.com 
2.  Hqvideoporn.com 
3.  Myadultcube.com 
4.  Mydirectcube.com 
5.  Mydirecttube.com 
6.  Pornotube8.net 
7.  Tube28.net 
8.  Adultvideotubes.net 
9.  Dasongs.net 
10.  Directcubeone.net 
11.  Directcubetwo.net 
12.  Pornotube30.net 
13.  Tube40.net 

Host: www.avxp-2008.net
IP:  78.159.99.79

Whois of IP  78.159.99.79 distibuting rogue antivirus Antivirurus XP 2008 :

org-name:       netdirect
org-type:       LIR
address:        netdirekt e. K.
                Kleyer Strasse 79 / Tor 14
                60326 Frankfurt
                Germany
phone:          +49 69 90556880
fax-no:         +49 69 905568822
e-mail:         ripe@netdirekt.de

Host: secure.innovagest2000sl.com
IP: 207.226.175.126

Whois of IP 207.226.175.126  selling rogue antivirus Antivirurus XP 2008 :

OrgName:    Beyond The Network America, Inc.
OrgID:      BNA-42
Address:    450 Springpark PL
Address:    Suite 100
City:       Herdon
StateProv:  VA
PostalCode: 20170
Country:    US

Antivirus XP 2008

 

Related Posts :

CleanThe.Net Recommends - Cesam Anti-Malware. Remove Virus Now!

Download Cesam Anti-Malware

Post a Comment