Antivirus 2009 rogue antivirus application

November 19, 2008 | Malware, Rogues

Antivirus 2009  a rogue antivirus application. To remove that rogue application viruses and antispyware use Kaspersky antivirus - http://cleanthe.net/how-to-remove-virus/

Antivirus 2009

Antivirus 2009

File v-codec.123.exe received on 11.19.2008 16:23:57 (CET)
Antivirus Version Last Update Result
AhnLab-V3 2008.11.18.2 2008.11.19 -
AntiVir 7.9.0.34 2008.11.19 -
Authentium 5.1.0.4 2008.11.18 -
Avast 4.8.1281.0 2008.11.18 -
AVG 8.0.0.199 2008.11.19 -
BitDefender 7.2 2008.11.19 -
CAT-QuickHeal 10.00 2008.11.19 -
ClamAV 0.94.1 2008.11.19 -
DrWeb 4.44.0.09170 2008.11.19 -
eSafe 7.0.17.0 2008.11.18 Suspicious File
eTrust-Vet 31.6.6216 2008.11.19 -
Ewido 4.0 2008.11.19 -
F-Prot 4.4.4.56 2008.11.18 -
F-Secure 8.0.14332.0 2008.11.19 -
Fortinet 3.117.0.0 2008.11.19 -
GData 19 2008.11.19 -
Ikarus T3.1.1.45.0 2008.11.19 Trojan-Downloader.Win32.CodecPack
K7AntiVirus 7.10.527 2008.11.18 -
Kaspersky 7.0.0.125 2008.11.19 -
McAfee 5438 2008.11.18 -
Microsoft 1.4104 2008.11.19 TrojanDownloader:Win32/Renos.BAH
NOD32 3624 2008.11.19 Win32/TrojanDownloader.Zlob.CVG
Norman 5.80.02 2008.11.19 -
Panda 9.0.0.4 2008.11.19 -
PCTools 4.4.2.0 2008.11.19 -
Prevx1 V2 2008.11.19 Malware Dropper
Rising 21.04.22.00 2008.11.19 -
SecureWeb-Gateway 6.7.6 2008.11.19 -
Sophos 4.35.0 2008.11.19 Troj/Dloadr-CAG
Sunbelt 3.1.1801.2 2008.11.14 -
Symantec 10 2008.11.19 Downloader
TheHacker 6.3.1.1.158 2008.11.19 -
TrendMicro 8.700.0.1004 2008.11.19 Possible_DLDER
VBA32 3.12.8.9 2008.11.19 -
ViRobot 2008.11.18.1474 2008.11.18 -
VirusBuster 4.5.11.0 2008.11.18 -
 
Additional information
File size: 50176 bytes
MD5…: eec2d22e39d75355539f7eb7ff384fc2
SHA1..: 0ba883d406a51f5194c1ea5df2f8d78f02a30342
SHA256: b396ab2fc5128eb3643b0e483bcefe146c2fc855e3658eba7ab2b83df1b81860
SHA512: a3f42f426d7df0688984b57c89953cafab9432fc91793328c0385bbb2b471e3a
4897f4fc4efa6045e9181df30d74f40d34bcbf23d6e7a4ca0e4ca01aa2386270
PEiD..: -
TrID..: File type identification
Win32 Executable Generic (42.3%)
Win32 Dynamic Link Library (generic) (37.6%)
Generic Win/DOS Executable (9.9%)
DOS Executable Generic (9.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
 
Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=45B34567006772C7C4750054B66A1E00137572E3

Antivirus 2009

Antivirus 2009

 

File A9installertest_77100102.exe received on 11.19.2008 16:24:06 (CET)
Antivirus Version Last Update Result
AhnLab-V3 2008.11.18.2 2008.11.19 -
AntiVir 7.9.0.34 2008.11.19 -
Authentium 5.1.0.4 2008.11.18 -
Avast 4.8.1281.0 2008.11.18 -
AVG 8.0.0.199 2008.11.19 -
BitDefender 7.2 2008.11.19 -
CAT-QuickHeal 10.00 2008.11.19 -
ClamAV 0.94.1 2008.11.19 -
DrWeb 4.44.0.09170 2008.11.19 -
eSafe 7.0.17.0 2008.11.18 -
eTrust-Vet 31.6.6216 2008.11.19 -
Ewido 4.0 2008.11.19 -
F-Prot 4.4.4.56 2008.11.18 -
F-Secure 8.0.14332.0 2008.11.19 -
Fortinet 3.117.0.0 2008.11.19 -
GData 19 2008.11.19 -
Ikarus T3.1.1.45.0 2008.11.19 -
K7AntiVirus 7.10.527 2008.11.18 -
Kaspersky 7.0.0.125 2008.11.19 -
McAfee 5438 2008.11.18 -
Microsoft 1.4104 2008.11.19 Trojan:Win32/FakeXPA
NOD32 3624 2008.11.19 -
Norman 5.80.02 2008.11.19 -
Panda 9.0.0.4 2008.11.19 -
PCTools 4.4.2.0 2008.11.19 -
Prevx1 V2 2008.11.19 -
Rising 21.04.22.00 2008.11.19 -
SecureWeb-Gateway 6.7.6 2008.11.19 -
Sophos 4.35.0 2008.11.19 -
Sunbelt 3.1.1801.2 2008.11.14 -
Symantec 10 2008.11.19 -
TheHacker 6.3.1.1.158 2008.11.19 -
TrendMicro 8.700.0.1004 2008.11.19 -
VBA32 3.12.8.9 2008.11.19 -
ViRobot 2008.11.18.1474 2008.11.18 -
VirusBuster 4.5.11.0 2008.11.18 -
 
Additional information
File size: 163840 bytes
MD5…: b58b7c0fca632601b7b6f22faf0c73ac
SHA1..: ea50267f8ccdb033d3b1a2c060cc238f084e23fa
SHA256: a67e4fe36e60fbe3db906591fbede08bae239c1afb55ebc715879e57d621debf
SHA512: e4f4a17190f92e9371ce6aa2e74bf4dc016c30071e4a061ff6dbac116a41e15d
bd64b95d9b4545b4b85ff07259a77158df2970c67d595db304cf368b0bfedc55
PEiD..: -
TrID..: File type identification
Win32 Executable Generic (42.3%)
Win32 Dynamic Link Library (generic) (37.6%)
Generic Win/DOS Executable (9.9%)
DOS Executable Generic (9.9%)
VXD Driver (0.1%)
PEInfo: PE Structure information

Host: imp-porntube.net
IP: 64.27.28.224

Whois:

OrgName:    Hollywood Interactive, Inc.
OrgID:      HLWD
Address:    600 W. 7th Street, Ste. 360
City:       Los Angeles
StateProv:  CA
PostalCode: 90017
Country:    US

NetRange:   64.27.0.0 - 64.27.31.255
CIDR:       64.27.0.0/19
NetName:    HOLLYWOOD-INTERACTIVE
NetHandle:  NET-64-27-0-0-1
Parent:     NET-64-0-0-0-0
NetType:    Direct Allocation
NameServer: NS1.CALPOP.COM
NameServer: NS2.CALPOP.COM
Comment:    ADDRESSES WITHIN THIS BLOCK ARE NON-PORTABLE
RegDate:    2000-01-10
Updated:    2004-09-13

RNOCHandle: CNO4-ARIN
RNOCName:   CalPOP Network Operations
RNOCPhone:  +1-213-627-1937
RNOCEmail:   noc@calpop.com

Other sites:

1.  Celebs4you-online2008.com 
2.  I-av-sscan2009.com 
3.  Imp-porntube.net 

Host: antivirusdefense.com
IP: 69.10.44.207

Whois:

OrgName:    Interserver, Inc
OrgID:      INTER-83
Address:    110 Meadowlands Pkwy
Address:    1st Floor
City:       Secaucus
StateProv:  NJ
PostalCode: 07094
Country:    US

Host: www.win-security-scanner.org
IP: 115.126.5.92

Whois:

OrgName:    Asia Pacific Network Information Centre
OrgID:      APNIC
Address:    PO Box 2131
City:       Milton
StateProv:  QLD
PostalCode: 4064
Country:    AU

Other sites:

1.  Spy-protector.org 
2.  Win-security-scanner.org 
3.  Spy-protector.biz 

Host: powerfulvirusremover2008.com
IP: 77.245.61.80

Whois:

descr:          Webair Internet Development company, Inc
country:        NL
org:            ORG-RII1-RIPE
admin-c:        RIIS1-RIPE
tech-c:         RIIS1-RIPE
status:         ALLOCATED PA
mnt-by:         RIPE-NCC-HM-MNT
mnt-lower:      GLOBALAXS-MNT
mnt-lower:      WEBAIRINC-MTL
mnt-domains:    MNT-RECURRING
mnt-routes:     MNT-RECURRING
source:         RIPE # Filtered

organisation:   ORG-RII1-RIPE
org-name:       Webair Internet Development company, Inc
org-type:       LIR
address:        Recurring International Inc
                Sagi Brody
                REDBUS INTERHOUSE (NETHERLANDS) B V GYROSCOOPWEG 2E
                AB 1042 AMSTERDAM
                Netherlands
phone:          +31 20 4804400
fax-no:         +15169385100

Other sites:

1.  Mysecureexpertcleaner.com 
2.  Pcvirusremover2008.com 
3.  Powerfulvirusremover2008.com 
4.  Prosecureexpertcleaner.com 
5.  Prosecureexpertcleanerpro.com 
6.  Registrydoctor2008-online.com 
7.  Registrydoctor2008-pro.com 
8.  Registrydoctor2008-scan.com 
9.  Registrydoctor2008.com 
10.  Registrydoctorpro2008.com 
11.  Secureexpertcleaner.com 
12.  Securefileshred.com 
13.  Securefileshredder.com 
14.  Securefileshredder2009.com 
15.  Securefilesshred.com 
16.  Securefilesshredder.com 
17.  Strongvirusremover2008.com 
18.  Supersecurefileshredder.com 
19.  Topregistrydoctor2008.com 
20.  Virusremover2008flash.com 
21.  Virusremover2008plus.com 
22.  Winsecureexpertcleaner.com 
23.  Yoursecureexpertcleaner.com 

Host: official-antivirus2009.com
IP: 84.243.196.136

Whois:

org-name:       PortNAP Internet Services
org-type:       OTHER
address:        Beverwaardseweg 232
address:        3077GD Rotterdam
address:        The Netherlands
phone:          +31.612928606
mnt-ref:        GFX-MNT
mnt-by:         GFX-MNT
source:         RIPE # Filtered

role:           GrafiX NOC
org:            ORG-GIB1-RIPE
address:        GrafiX Internet B.V.
address:        Stationsplein 20
address:        2907 MJ  Capelle aan den IJssel
phone:          +31 10 2640210
fax-no:         +31 10 2640211

Host: softwarebillingservice.com
IP: 63.219.177.214

Whois of softwarebillingservice.com

Registration Service Provided By: ERDOMAIN.COM
Contact: +49.3036741521
Website: http://www.erdomain.com

Domain Name: SOFTWAREBILLINGSERVICE.COM

Registrant:
    N/A
    Viktor Temchenko        (temchenkoviktor@googlemail.com)
    Pr. Geroev Tryda
    Kharkov
    Kharkiv Oblast,01001
    UA
    Tel. +380.936328480

Creation Date: 03-Nov-2008
Expiration Date: 03-Nov-2009

Whois of 63.219.177.214

OrgName:    Beyond The Network America, Inc.
OrgID:      BNA-42
Address:    450 Springpark PL
Address:    Suite 100
City:       Herdon
StateProv:  VA
PostalCode: 20170
Country:    US

Antivirus 2009

Antivirus 2009 from Pandora software

Antivirus 2009

Windefender 2009 rogue antivirus application

November 18, 2008 | Malware, Rogues

Windefender 2009 is a rogue antivirus application. To remove that rogue application viruses and antispyware use Kaspersky antivirus - http://cleanthe.net/how-to-remove-virus/

Windefender 2009

Windefender 2009

File c-setup.exe received on 11.18.2008 18:08:03 (CET)
Antivirus Version Last Update Result
AhnLab-V3 2008.11.18.2 2008.11.18 -
AntiVir 7.9.0.31 2008.11.18 TR/BHO.Gen
Authentium 5.1.0.4 2008.11.18 -
Avast 4.8.1281.0 2008.11.18 Win32:Trojan-gen {Other}
AVG 8.0.0.199 2008.11.18 Downloader.Zlob_r.DQ
BitDefender 7.2 2008.11.18 Trojan.BHO.Agent.AL
CAT-QuickHeal 10.00 2008.11.18 -
ClamAV 0.94.1 2008.11.18 -
DrWeb 4.44.0.09170 2008.11.18 Trojan.MulDrop.23099
eSafe 7.0.17.0 2008.11.18 Suspicious File
eTrust-Vet 31.6.6210 2008.11.14 -
Ewido 4.0 2008.11.18 -
F-Prot 4.4.4.56 2008.11.18 -
F-Secure 8.0.14332.0 2008.11.18 Trojan-Dropper.Win32.Agent.zsl
Fortinet 3.117.0.0 2008.11.18 -
GData 19 2008.11.18 Trojan.BHO.Agent.AL
Ikarus T3.1.1.45.0 2008.11.18 -
K7AntiVirus 7.10.527 2008.11.18 -
Kaspersky 7.0.0.125 2008.11.18 Trojan-Dropper.Win32.Agent.zsl
McAfee 5437 2008.11.17 -
Microsoft 1.4104 2008.11.17 TrojanDownloader:Win32/Renos.DU
NOD32 3622 2008.11.18 a variant of Win32/Adware.IeDefender.NHN
Norman 5.80.02 2008.11.18 W32/DLoader.KWIR
Panda 9.0.0.4 2008.11.17 Suspicious file
PCTools 4.4.2.0 2008.11.18 -
Prevx1 V2 2008.11.18 -
Rising 21.04.12.00 2008.11.18 -
SecureWeb-Gateway 6.7.6 2008.11.18 Trojan.BHO.Gen
Sophos 4.35.0 2008.11.18 -
Sunbelt 3.1.1801.2 2008.11.14 -
Symantec 10 2008.11.18 Downloader
TheHacker 6.3.1.1.157 2008.11.18 -
TrendMicro 8.700.0.1004 2008.11.18 PAK_Generic.001
VBA32 3.12.8.9 2008.11.18 -
ViRobot 2008.11.18.1474 2008.11.18 Dropper.Agent.57351
VirusBuster 4.5.11.0 2008.11.18 Trojan.Renos.Gen.16
 
Additional information
File size: 57351 bytes
MD5…: 1a9583d617ff88abc9545a3900236157
SHA1..: 4094537a779cf871c5093cc56db6cfc026ea72f6
SHA256: 9f98c152410921131b66771f600b719b4719d4b715d09668f85ea60ac77f133d
SHA512: da13cd6ed92b20e0d448f93267a40a12b7f663ade1e2be7f3cdc188058a0d58c
36e34f0243a7213ee6ce347e3e4753d36a2fcdaefad4e5706a9cf2c050beeb5f
PEiD..: UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser
TrID..: File type identification
UPX compressed Win32 Executable (39.5%)
Win32 EXE Yoda’s Crypter (34.3%)
Win32 Executable Generic (11.0%)
Win32 Dynamic Link Library (generic) (9.8%)
Generic Win/DOS Executable (2.5%)
PEInfo: PE Structure information( base data )
entrypointaddress.: 0×429360
timedatestamp…..: 0×491fe9c9 (Sun Nov 16 09:37:13 2008)
machinetype…….: 0×14c (I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
UPX0 0×1000 0×1c000 0×0 0.00 d41d8cd98f00b204e9800998ecf8427e
UPX1 0×1d000 0xd000 0xc600 7.86 296d10f178fd443321b930fe12aedbdd
.rsrc 0×2a000 0×2000 0×1600 3.31 251ab64ce46cbb40a0ae5643b8a4fd11

( 3 imports )
> KERNEL32.DLL: LoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree, ExitProcess
> ADVAPI32.dll: RegCloseKey
> SHELL32.dll: ShellExecuteA

( 0 exports )

packers (Kaspersky): PE_Patch.UPX, UPX
packers (F-Prot): UPX

Windefender 2009

File WinDefender2009.exe received on 11.18.2008 18:11:48 (CET)
Antivirus Version Last Update Result
AhnLab-V3 2008.11.18.2 2008.11.18 -
AntiVir 7.9.0.31 2008.11.18 DR/Fraud.WinDefender.2009
Authentium 5.1.0.4 2008.11.18 -
Avast 4.8.1281.0 2008.11.18 Win32:Trojan-gen {Other}
AVG 8.0.0.199 2008.11.18 Generic3.ADNC
BitDefender 7.2 2008.11.18 Trojan.Generic.1133460
CAT-QuickHeal 10.00 2008.11.18 -
ClamAV 0.94.1 2008.11.18 -
DrWeb 4.44.0.09170 2008.11.18 Trojan.Fakealert.2116
eSafe 7.0.17.0 2008.11.18 -
eTrust-Vet 31.6.6209 2008.11.14 -
Ewido 4.0 2008.11.18 -
F-Prot 4.4.4.56 2008.11.18 -
F-Secure 8.0.14332.0 2008.11.18 FraudTool.Win32.WinDefender.2009
Fortinet 3.117.0.0 2008.11.18 -
GData 19 2008.11.18 Trojan.Generic.1133460
Ikarus T3.1.1.45.0 2008.11.18 Trojan.Win32.Delflob.I
K7AntiVirus 7.10.527 2008.11.18 -
Kaspersky 7.0.0.125 2008.11.18 not-a-virus:FraudTool.Win32.WinDefender.2009
McAfee 5437 2008.11.17 -
Microsoft 1.4104 2008.11.17 Trojan:Win32/Delflob.I
NOD32 3622 2008.11.18 probably a variant of Win32/Adware.IeDefender.NHA
Norman 5.80.02 2008.11.18 -
Panda 9.0.0.4 2008.11.17 Adware/WinDefender2009
PCTools 4.4.2.0 2008.11.18 -
Prevx1 V2 2008.11.18 -
Rising 21.04.12.00 2008.11.18 -
SecureWeb-Gateway 6.7.6 2008.11.18 Trojan.Dropper.Fraud.WinDefender.2009
Sophos 4.35.0 2008.11.18 IE Defender
Sunbelt 3.1.1801.2 2008.11.14 -
Symantec 10 2008.11.18 WinDefender
TheHacker 6.3.1.1.157 2008.11.18 -
TrendMicro 8.700.0.1004 2008.11.18 -
VBA32 3.12.8.9 2008.11.18 Hoax.Win32.WinDefender2009
ViRobot 2008.11.18.1474 2008.11.18 Adware.WinDefender.R.1726125
VirusBuster 4.5.11.0 2008.11.18 -
 
Additional information
File size: 1726125 bytes
MD5…: 9f74ce5fb169ae4a78d1d3fca0c4768e
SHA1..: 31f7ef93e02394baa92f3f4aee84f907755580f8
SHA256: 1c53eb545a96cd85f68a0bd2b7b08d6b44e7f05a465f97a40bb2932e6b2da1a0
SHA512: 1542a404860a9b10248cd6bcf53b9e98eae73abd86c8983d23811da322ef3454
362053944c853930f667c3868d71311c693e7d893080364a41ddd7ba8340e727
PEiD..: -
TrID..: File type identification
Win32 Executable MS Visual C++ (generic) (65.2%)
Win32 Executable Generic (14.7%)
Win32 Dynamic Link Library (generic) (13.1%)
Generic Win/DOS Executable (3.4%)
DOS Executable Generic (3.4%)
PEInfo: PE Structure information
( 0 exports )
ThreatExpert info: http://www.threatexpert.com/report.aspx?md5=9f74ce5fb169ae4a78d1d3fca0c4768e

Windefender 2009

Windefender 2009

Host: mymostprivatevideo.com
IP: 78.157.141.6

Whois:

role:           UltraNet Hostmaster
address:        UltraNet SIA
                Aizkraukles 23
                Riga, LV-1006
                Latvia
phone:          +371 67543003
fax-no:         +371 67594435
e-mail:         hostmaster@ultranet.lv
admin-c:        AS28817-RIPE
admin-c:        MS16883-RIPE
tech-c:         AS28817-RIPE
nic-hdl:        UNHM-RIPE
mnt-by:         UN-MNT
source:         RIPE # Filtered

Host: windefender-2009.com
IP: 200.63.45.55

Whois:

status:      reallocated
owner:       Ricardo Carreras
ownerid:     HN-RICA-LACNIC
responsible: Honduras Web
address:     P.O.Box: 1142 La Ceiba, #37 street., 1142, 37
address:     00000 - Tegucigalpa - TE
country:     HN
phone:       +504  9815-3645 []
owner-c:     RIC9
tech-c:      RIC9
abuse-c:     RIC9
created:     20080630
changed:     20080630
inetnum-up:  200.63.40/21

nic-hdl:     RIC9
person:      Ricardo Carreras
e-mail:      hn-rica@ONLINEABUSECENTER.COM

Host: windefender2009.com
IP:  200.63.45.132

Whois:

status:      reallocated
owner:       Ricardo Carreras
ownerid:     HN-RICA-LACNIC
responsible: Honduras Web
address:     P.O.Box: 1142 La Ceiba, #37 street., 1142, 37
address:     00000 - Tegucigalpa - TE
country:     HN
phone:       +504  9815-3645 []
owner-c:     RIC9
tech-c:      RIC9
abuse-c:     RIC9
created:     20080630
changed:     20080630
inetnum-up:  200.63.40/21

nic-hdl:     RIC9
person:      Ricardo Carreras
e-mail:      hn-rica@ONLINEABUSECENTER.COM

Windefender 2009

PRO Antispyware 2009 rogue antispyware application

November 18, 2008 | Malware, Rogues

PRO Antispyware 2009 is a rogue antispyware. To remove that rogue application viruses and antispyware use Kaspersky antivirus - http://cleanthe.net/how-to-remove-virus/

Pro ANtispyware 2009

 

File setup_225_7777_.exe received on 11.18.2008 12:09:21 (CET)
Antivirus Version Last Update Result
AhnLab-V3 2008.11.18.2 2008.11.18 -
AntiVir 7.9.0.31 2008.11.18 -
Authentium 5.1.0.4 2008.11.18 -
Avast 4.8.1281.0 2008.11.17 -
AVG 8.0.0.199 2008.11.17 -
BitDefender 7.2 2008.11.18 -
CAT-QuickHeal 10.00 2008.11.18 -
ClamAV 0.94.1 2008.11.18 -
DrWeb 4.44.0.09170 2008.11.18 -
eSafe 7.0.17.0 2008.11.17 -
eTrust-Vet 31.6.6210 2008.11.14 -
Ewido 4.0 2008.11.17 -
F-Prot 4.4.4.56 2008.11.17 W32/SuspPack.H.gen!Eldorado
F-Secure 8.0.14332.0 2008.11.18 -
Fortinet 3.117.0.0 2008.11.18 -
GData 19 2008.11.18 -
Ikarus T3.1.1.45.0 2008.11.18 -
K7AntiVirus 7.10.526 2008.11.15 -
Kaspersky 7.0.0.125 2008.11.18 -
McAfee 5437 2008.11.17 -
Microsoft 1.4104 2008.11.17 Program:Win32/WinSpywareProtect
NOD32 3621 2008.11.18 -
Norman 5.80.02 2008.11.17 -
Panda 9.0.0.4 2008.11.17 Suspicious file
PCTools 4.4.2.0 2008.11.17 -
Prevx1 V2 2008.11.18 -
Rising 21.04.12.00 2008.11.18 -
SecureWeb-Gateway 6.7.6 2008.11.18 -
Sophos 4.35.0 2008.11.18 -
Sunbelt 3.1.1801.2 2008.11.14 -
Symantec 10 2008.11.18 -
TheHacker 6.3.1.1.157 2008.11.18 -
TrendMicro 8.700.0.1004 2008.11.18 -
VBA32 3.12.8.9 2008.11.17 -
ViRobot 2008.11.18.1474 2008.11.18 -
VirusBuster 4.5.11.0 2008.11.17 -
 
Additional information
File size: 114688 bytes
MD5…: 5113da8324f92352294aee4f47a532b2
SHA1..: fc2bd52925959ee5061e412d12754ccc120d7925
SHA256: 9506866e9b3cda9e1867c34e091dc1c662032395e1dcf857627fa31547c76bd3
SHA512: ddb22cefe217431451134787847b8fc7b697bb154778cb41b63bc0d2caa70aa6
6d544bb2cf0b89c06d47ba7c56345b0408ac08354e44eddd0e20e17ca74a822e
PEiD..: -
TrID..: File type identification
Win32 Executable Generic (38.4%)
Win32 Dynamic Link Library (generic) (34.2%)
Clipper DOS Executable (9.1%)
Generic Win/DOS Executable (9.0%)
DOS Executable Generic (9.0%)
PEInfo: PE Structure information

Pro ANtispyware 2009

Host: scan.scannerantispyware.com
IP: 78.26.179.233

Whois:

role:           Renome Service Tech Staff
address:        Kosvennaya str., 78, Odessa, Ukraine, 65000
org:            ORG-RA159-RIPE
phone:          +380487597596
fax-no:         +380487597596
mnt-by:         RENOME-MNT
abuse-mailbox:  abuse@odessa.tv
admin-c:        WU-RIPE
admin-c:        GA-RIPE
tech-c:         WU-RIPE
nic-hdl:        RSM-RIPE
source:         RIPE # Filtered

 

Host: files.download-antispyware.com
IP: 78.157.142.81

Whois:

netname:        VDHOST
descr:          VdHost Ltd.
descr:          abuse@vdhost.info
country:        LV
admin-c:        AV2990-RIPE
tech-c:         AV2990-RIPE
status:         ASSIGNED PA
mnt-by:         UN-MNT
source:         RIPE # Filtered

person:         Arturs Vavilovs
address:        Riga
phone:          +371 29653077
e-mail:         admin@vdhost.info
nic-hdl:        AV2990-RIPE
mnt-by:         UN-MNT
source:         RIPE # Filtered

Host: sales.proantispyware-2009-buy.com
IP: 216.195.42.226

Whois:

OrgName:    APS Telecom
OrgID:      APSTE
Address:    8130 SW BEAVERTON-HILLSDALE HWY
City:       PORTLAND
StateProv:  OR
PostalCode: 97225
Country:    US

Host: secure.websecurebilling.com
IP: 209.8.45.146

Whois of websecurebilling.com :

  Domain Name: WEBSECUREBILLING.COM
   Registrar: REGTIME LTD.
   Whois Server: whois.regtime.net
   Referral URL: http://www.webnames.ru
   Name Server: NS1.WEBSECUREBILLING.COM
   Name Server: NS2.WEBSECUREBILLING.COM
   Status: ok
   Updated Date: 11-nov-2008
   Creation Date: 07-nov-2008
   Expiration Date: 07-nov-2009
  
Whois 209.8.45.146:

OrgName:    Beyond The Network America, Inc.
OrgID:      BNA-42
Address:    450 Springpark PL
Address:    Suite 100
City:       Herdon
StateProv:  VA
PostalCode: 20170
Country:    US

Pro ANtispyware 2009

PRO Antispyware 2009 from Pandora software

Pro ANtispyware 2009

 

Antispyware PRO XP rogue antispyware application

November 17, 2008 | Malware, Rogues

Antispyware PRO XP is a rogue antispyware. To remove that rogue application viruses and antispyware use Kaspersky antivirus - http://cleanthe.net/how-to-remove-virus/

Antispyware PRO XP

Antispyware PRO XP

File setup_100525_3_.exe received on 11.17.2008 18:37:56 (CET)
Antivirus Version Last Update Result
AhnLab-V3 2008.11.18.0 2008.11.17 -
AntiVir 7.9.0.31 2008.11.17 -
Authentium 5.1.0.4 2008.11.17 -
Avast 4.8.1281.0 2008.11.16 -
AVG 8.0.0.199 2008.11.17 -
BitDefender 7.2 2008.11.17 -
CAT-QuickHeal 10.00 2008.11.15 -
ClamAV 0.94.1 2008.11.17 -
DrWeb 4.44.0.09170 2008.11.17 -
eSafe 7.0.17.0 2008.11.17 -
eTrust-Vet 31.6.6210 2008.11.14 -
Ewido 4.0 2008.11.17 -
F-Prot 4.4.4.56 2008.11.17 W32/SuspPack.H.gen!Eldorado
F-Secure 8.0.14332.0 2008.11.17 -
Fortinet 3.117.0.0 2008.11.15 -
GData 19 2008.11.17 -
Ikarus T3.1.1.45.0 2008.11.17 -
K7AntiVirus 7.10.526 2008.11.15 -
Kaspersky 7.0.0.125 2008.11.17 -
McAfee 5436 2008.11.16 -
Microsoft 1.4104 2008.11.17 Program:Win32/WinSpywareProtect
NOD32 3618 2008.11.17 -
Norman 5.80.02 2008.11.14 -
Panda 9.0.0.4 2008.11.16 Suspicious file
PCTools 4.4.2.0 2008.11.17 -
Prevx1 V2 2008.11.17 -
Rising 21.04.02.00 2008.11.17 -
SecureWeb-Gateway 6.7.6 2008.11.17 -
Sophos 4.35.0 2008.11.17 -
Sunbelt 3.1.1801.2 2008.11.14 -
Symantec 10 2008.11.17 -
TheHacker 6.3.1.1.155 2008.11.15 -
TrendMicro 8.700.0.1004 2008.11.17 -
VBA32 3.12.8.9 2008.11.17 -
ViRobot 2008.11.17.1472 2008.11.17 -
VirusBuster 4.5.11.0 2008.11.17 -
 
Additional information
File size: 122880 bytes
MD5…: cbcaa0f14b3ad25036a0e8042fe0e9d5
SHA1..: ecea91c245222dc67eb5818d6986169a6d7725f1
SHA256: 1af2c9791b8fe7698871249cf9ee6838ee9997e846b2f901a2d1d1bb0c2ea74c
SHA512: 06d550cbee18719b4d34a5bade7b0001da93fb680e4191caac796e711fb35685
9ef5136e0070e91893cd40d78c1bf7800ae71a3f30754ae160ec0facaa02fc43
PEiD..: -
TrID..: File type identification
Win32 Executable Generic (38.4%)
Win32 Dynamic Link Library (generic) (34.2%)
Clipper DOS Executable (9.1%)
Generic Win/DOS Executable (9.0%)
DOS Executable Generic (9.0%)
PEInfo: PE Structure information

Antispyware PRO XP

Host: scan.antispyware-free-scanner.com
IP: 78.26.179.230

Whois:

organisation:   ORG-RA159-RIPE
org-name:       Renome-Service
org-type:       LIR
descr:          Renome-Service: Joint Multimedia Cable Network
address:        Renome Service
                Andrew Gaidulyan
                Kosvennaya str., 78
                65000 Odessa
                UKRAINE
phone:          +3 80487597596
fax-no:         +3 80487597596
abuse-mailbox:  abuse@odessa.tv
admin-c:        GA-RIPE
admin-c:        WU-RIPE
admin-c:        WU-RIPE
mnt-ref:        RENOME-MNT
mnt-ref:        RIPE-NCC-HM-MNT
mnt-by:         RIPE-NCC-HM-MNT
source:         RIPE # Filtered

 

Host: files.pc-security-downloads.com
IP: 78.157.142.80

Whois:

inetnum:        78.157.142.0 - 78.157.142.255
netname:        VDHOST
descr:          VdHost Ltd.
descr:          abuse@vdhost.info
country:        LV
admin-c:        AV2990-RIPE
tech-c:         AV2990-RIPE
status:         ASSIGNED PA
mnt-by:         UN-MNT
source:         RIPE # Filtered

person:         Arturs Vavilovs
address:        Riga
phone:          +371 29653077
e-mail:         admin@vdhost.info
nic-hdl:        AV2990-RIPE
mnt-by:         UN-MNT
source:         RIPE # Filtered

 

Host: sales.buy-antispyware-pro-xp.com
IP: 216.195.42.223

Whois:

OrgName:    APS Telecom
OrgID:      APSTE
Address:    8130 SW BEAVERTON-HILLSDALE HWY
City:       PORTLAND
StateProv:  OR
PostalCode: 97225
Country:    US

Host: secure.paymentbit.net
IP: 216.195.56.175

Whois of paymentbit.net

Registrant:
         Joana Termon  (4epmck6ysxu@privateregistration.srsplus.com)
        Billing Group, Corp
        ATTN: paymentbit.net
        c/o SRSPlus Private Registration
        P.O. Box 447
        Herndon, VA 20172-0447
        570-708-8760

Domain Name: paymentbit.net

 

Whois of IP 216.195.56.175:

OrgName:    APS Telecom
OrgID:      APSTE
Address:    8130 SW BEAVERTON-HILLSDALE HWY
City:       PORTLAND
StateProv:  OR
PostalCode: 97225
Country:    US

NetRange:   216.195.32.0 - 216.195.63.255
CIDR:       216.195.32.0/19
NetName:    APS-EPSI
NetHandle:  NET-216-195-32-0-1
Parent:     NET-216-0-0-0-0
NetType:    Direct Allocation
NameServer: NS1.3FN.NET
NameServer: NS2.3FN.NET
Comment:    send abuse issues to abuse@3fn.net, send network
Comment:    issue to noc@3fn.net
RegDate:    2003-11-05
Updated:    2004-09-17

RTechHandle: NSW-ARIN
RTechName:   Swen, Nash
RTechPhone:  +1-800-539-8209
RTechEmail:  noc@apxtelecom.com

OrgTechHandle: NSW-ARIN
OrgTechName:   Swen, Nash
OrgTechPhone:  +1-800-539-8209
OrgTechEmail:  noc@apxtelecom.com

Other sites:

1.  1softwarespot.com 
2.  Adult-billing.com 
3.  Bestsoftclub.com 
4.  Billhlp.com 
5.  Billingcenteronline.com 
6.  Billinghost.net 
7.  Billingintegrator.com 
8.  Billingmill.com 
9.  Billingserviceonline.com 
10.  Billingsquad.net 
11.  Billinternet.com 
12.  Billsvc.com 
13.  Customerhlp.com 
14.  Dopaymentsonline.com 
15.  Ebillingcenter.com 
16.  Fantazybill.com 
17.  Interbills.com 
18.  Justnetbilling.net 
19.  Legalbillingsystems.com 
20.  Mainbillingcenter.com 
21.  Megafixer.com 
22.  Orderhlp.com 
23.  Paymentbit.com 
24.  Paymentbit.net 
25.  Paymentforge.com 
26.  Safepaymentsonline.com 
27.  Softwbill.com 
28.  Spankyhosting.com 
29.  Support-wizard.com 
30.  Truebillingservices.com 

Antispyware PRO XP

DNS changer virus and commercial banner exchanger

November 17, 2008 | Malware, Rogues

DNS changer virus. Stay away from following IPS and Domains!

To remove virus DNS changer use Kaspersky Antivirus http://cleanthe.net/how-to-remove-virus/

DNS Changer

DNS Changer

File FlashPlayer.v..exe received on 11.17.2008 15:40:33 (CET)
Antivirus Version Last Update Result
AhnLab-V3 2008.11.14.3 2008.11.17 -
AntiVir 7.9.0.31 2008.11.17 TR/DNSChanger.hkx
Authentium 5.1.0.4 2008.11.17 -
Avast 4.8.1281.0 2008.11.16 -
AVG 8.0.0.199 2008.11.17 -
BitDefender 7.2 2008.11.17 -
CAT-QuickHeal 10.00 2008.11.15 -
ClamAV 0.94.1 2008.11.17 -
DrWeb 4.44.0.09170 2008.11.17 -
eSafe 7.0.17.0 2008.11.16 -
eTrust-Vet 31.6.6210 2008.11.14 -
Ewido 4.0 2008.11.17 -
F-Prot 4.4.4.56 2008.11.17 -
F-Secure 8.0.14332.0 2008.11.17 -
Fortinet 3.117.0.0 2008.11.15 -
GData 19 2008.11.17 -
Ikarus T3.1.1.45.0 2008.11.17 -
K7AntiVirus 7.10.526 2008.11.15 -
Kaspersky 7.0.0.125 2008.11.17 -
McAfee 5436 2008.11.16 -
Microsoft 1.4104 2008.11.17 -
NOD32 3617 2008.11.17 a variant of Win32/Kryptik.BT
Norman 5.80.02 2008.11.14 -
Panda 9.0.0.4 2008.11.16 -
PCTools 4.4.2.0 2008.11.17 -
Rising 21.04.02.00 2008.11.17 -
SecureWeb-Gateway 6.7.6 2008.11.17 -
Sophos 4.35.0 2008.11.17 -
Sunbelt 3.1.1801.2 2008.11.14 -
Symantec 10 2008.11.17 -
TheHacker 6.3.1.1.155 2008.11.15 -
TrendMicro 8.700.0.1004 2008.11.17 -
ViRobot 2008.11.17.1472 2008.11.17 -
VirusBuster 4.5.11.0 2008.11.16 -
 
Additional information
File size: 111051 bytes
MD5…: 7228ad946222e4323220402169b52755
SHA1..: 9e4c8906373344a12edf98d46aa2ace3eadc9068
SHA256: b1dd1c69c8f29e52cdf69e305569cc8872bc4403a84ab0b4c355fb1b50f32602
SHA512: cf8aa210256dad94abb1eacda2b1befc5e6670e59ed0c58200045a4f1583bcd0
7ded4742bcdfc94e43b395aa1623019fbfb9380d4e456ced15c8299ef2584528
PEiD..: -
TrID..: File type identification
Win32 Executable MS Visual C++ (generic) (65.2%)
Win32 Executable Generic (14.7%)
Win32 Dynamic Link Library (generic) (13.1%)
Generic Win/DOS Executable (3.4%)
DOS Executable Generic (3.4%)
 

DNS Changer

Host: porntube08.com
IP: 99.198.96.54

Whois:

OrgName:    SingleHop, Inc.
OrgID:      SINGL-8
Address:    223 West Jackson Street
Address:    Suite 1014
City:       Chicago
StateProv:  IL
PostalCode: 60606
Country:    US

NetRange:   99.198.96.0 - 99.198.127.255
CIDR:       99.198.96.0/19
OriginAS:   AS32475
NetName:    SINGLEHOP
NetHandle:  NET-99-198-96-0-1
Parent:     NET-99-0-0-0-0
NetType:    Direct Allocation
NameServer: NS1.SINGLEHOP.COM
NameServer: NS2.SINGLEHOP.COM
Comment:   
RegDate:    2008-08-14
Updated:    2008-08-14

RAbuseHandle: NETWO1546-ARIN
RAbuseName:   Network Operations
RAbusePhone:  +1-866-817-2811

Other sites:

1.  Porn-toube.com 
2.  Porntube08.com 
3.  Porntube09.com 
4.  Sex-toube.com 
5.  Sextoubi.com 

Host: pillsexpert.com
IP: 66.230.181.160

Rogue DNS 85.255.112.12 and 85.255.112.132

org-name:       UkrTeleGroup Ltd.
org-type:       LIR
address:        UkrTeleGroup Ltd.
                Mechnikova 58/5
                65029 Odessa
                Ukraine
phone:          +380487311011
fax-no:         +380487502499
mnt-ref:        UKRTELE-MNT
mnt-ref:        RIPE-NCC-HM-MNT
mnt-by:         RIPE-NCC-HM-MNT
source:         RIPE # Filtered

DNS Changer

Antivirus PRO 2009 rogue antivirus application

November 15, 2008 | Malware, Rogues

Antivirus PRO 2009  a rogue antivirus application. To remove that rogue application viruses and antispyware use Kaspersky antivirus - http://cleanthe.net/how-to-remove-virus/

Antivirus PRO 2009

Antivirus PRO 2009

Antivirus PRO 2009

 

File zcodec.1479.exe received on 11.15.2008 15:53:11 (CET)
Antivirus Version Last Update Result
AhnLab-V3 2008.11.14.3 2008.11.14 -
AntiVir 7.9.0.31 2008.11.14 -
Authentium 5.1.0.4 2008.11.15 -
Avast 4.8.1281.0 2008.11.14 -
AVG 8.0.0.199 2008.11.15 -
BitDefender 7.2 2008.11.15 -
CAT-QuickHeal 10.00 2008.11.15 -
ClamAV 0.94.1 2008.11.15 -
DrWeb 4.44.0.09170 2008.11.15 -
eSafe 7.0.17.0 2008.11.13 Suspicious File
eTrust-Vet 31.6.6209 2008.11.14 -
Ewido 4.0 2008.11.15 -
F-Prot 4.4.4.56 2008.11.14 -
F-Secure 8.0.14332.0 2008.11.15 -
Fortinet 3.117.0.0 2008.11.15 -
GData 19 2008.11.15 -
Ikarus T3.1.1.45.0 2008.11.15 -
K7AntiVirus 7.10.526 2008.11.15 -
Kaspersky 7.0.0.125 2008.11.15 -
McAfee 5434 2008.11.14 -
Microsoft 1.4104 2008.11.15 TrojanDownloader:Win32/Renos.BAH
NOD32 3615 2008.11.15 -
Norman 5.80.02 2008.11.14 -
Panda 9.0.0.4 2008.11.15 -
PCTools 4.4.2.0 2008.11.15 -
Prevx1 V2 2008.11.15 -
Rising 21.03.42.00 2008.11.14 -
SecureWeb-Gateway 6.7.6 2008.11.14 -
Sophos 4.35.0 2008.11.15 -
Sunbelt 3.1.1801.2 2008.11.14 -
Symantec 10 2008.11.15 -
TheHacker 6.3.1.1.152 2008.11.13 -
TrendMicro 8.700.0.1004 2008.11.14 Possible_DLDER
VBA32 3.12.8.9 2008.11.14 -
ViRobot 2008.11.15.1470 2008.11.15 -
VirusBuster 4.5.11.0 2008.11.14 -
 
Additional information
File size: 49152 bytes
MD5…: ca94d67ba435fe1870ffa720fb823b33
SHA1..: 2201dcbdeb217c3d8feceeed6e943946b972b001
SHA256: 26f6eb0f2810f97333170078e08eae1540c241257618562d61fd0fc22c8d405d
SHA512: 257d38ded0060021b2f20716e39f1cdfde0448b0c3089b23bca628b4f0e1c6f7
8188d21c04a26b95169d4b9934e8c72c4a6743ea2fd938db4ca8baa0a329d1d4
PEiD..: -
TrID..: File type identification
Win32 Executable Generic (42.3%)
Win32 Dynamic Link Library (generic) (37.6%)
Generic Win/DOS Executable (9.9%)
DOS Executable Generic (9.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
 

 

Antivirus PRO 2009

Host: new-porn-tubeportal2008.net
IP: 89.149.228.201

Whois:

descr:          netdirect Frankfurt, DE
origin:         AS28753
org:            ORG-nA8-RIPE
mnt-lower:      NETDIRECT-MNT
mnt-routes:     NETDIRECT-MNT
mnt-by:         NETDIRECT-MNT
source:         RIPE # Filtered

organisation:   ORG-nA8-RIPE
org-name:       netdirect
org-type:       LIR
address:        netdirekt e. K.
                Kleyer Strasse 79 / Tor 14
                60326 Frankfurt
                Germany
phone:          +49 69 90556880
fax-no:         +49 69 905568822
e-mail:         ripe@netdirekt.de

Other sites:

1.  Celebrity-on-video-08.net 
2.  Domain5123.net 
3.  I-av-scanner2008.net 
4.  New-porn-tubeportal2008.net 

Host: down-soft-index.com
IP: 216.195.41.60

Whois:

OrgName:    APS Telecom
OrgID:      APSTE
Address:    8130 SW BEAVERTON-HILLSDALE HWY
City:       PORTLAND
StateProv:  OR
PostalCode: 97225
Country:    US

Other sites:

1.  Down-soft-index.com 
2.  Downsoftindex.com 

Host: av-pro-2009.com
IP: 92.48.201.50

Whois:

netname:        NEWRACK-NL
descr:          NewRack.eu NL department
country:        NL
admin-c:        SVS148-RIPE
tech-c:         SVS148-RIPE
status:         ASSIGNED PA
mnt-by:         WEDARE-MNT
source:         RIPE # Filtered

person:         Sergey V. Smirnoff
address:        OOO “Ronetel”
address:        Lenina 129 o. 17
address:        Moscow
address:        Russia
phone:          +852 812 4838
fax-no:         +852 812 4838
abuse-mailbox:  abuse@newrack.eu

 

Other sites:

1.  Av-pro-2009.com 
2.  Avpro2009.com 

Host: secure.soft-payments.com
IP: 92.48.201.52

Whois of soft-payments.com:

Domain name: soft-payments.com

Registrant Contact:
   Matthew Charles
   Matthew Charles monster@feedosmail.com
   +380.930772466 fax: +380.930772466
   30 Leicester Square
   London UK WC2H 7LA
   gb

Administrative Contact:
   Villi Mikoca monster@feedosmail.com
   +1.8821121128 fax: +1.8821121128
   3113 po box
   New York NY 10017
   us

Technical Contact:
   Villi Mikoca monster@feedosmail.com
   +1.8821121128 fax: +1.8821121128
   3113 po box
   New York NY 10017
   us

Billing Contact:
   Villi Mikoca monster@feedosmail.com
   +1.8821121128 fax: +1.8821121128
   3113 po box
   New York NY 10017
   us

Whois of 92.48.201.52:

OrgName:    APS Telecom
OrgID:      APSTE
Address:    8130 SW BEAVERTON-HILLSDALE HWY
City:       PORTLAND
StateProv:  OR
PostalCode: 97225
Country:    US

 

Antivirus PRO 2009

Antivirus PRO 2009

Antivirus 2009 rogue antivirus application

November 15, 2008 | Malware, Rogues

Antivirus 2009  a rogue antivirus application. To remove that rogue application viruses and antispyware use Kaspersky antivirus - http://cleanthe.net/how-to-remove-virus/

Antivirus 2009

File A9installer_880649.exe received on 11.15.2008 14:03:48 (CET)
Antivirus Version Last Update Result
AhnLab-V3 2008.11.14.3 2008.11.14 -
AntiVir 7.9.0.31 2008.11.14 TR/Dldr.FraudLoad.vdlc
Authentium 5.1.0.4 2008.11.15 W32/FakeAV.FM
Avast 4.8.1281.0 2008.11.14 Win32:Trojan-gen {Other}
AVG 8.0.0.199 2008.11.14 Downloader.Agent.AOYR
BitDefender 7.2 2008.11.15 -
CAT-QuickHeal 10.00 2008.11.15 -
ClamAV 0.94.1 2008.11.15 -
DrWeb 4.44.0.09170 2008.11.15 -
eSafe 7.0.17.0 2008.11.13 Win32.FraudLoad.vdlc
eTrust-Vet 31.6.6210 2008.11.14 -
Ewido 4.0 2008.11.15 -
F-Prot 4.4.4.56 2008.11.14 W32/FakeAV.FM
F-Secure 8.0.14332.0 2008.11.15 Trojan-Downloader.Win32.FraudLoad.vdlc
Fortinet 3.117.0.0 2008.11.15 -
GData 19 2008.11.15 Win32:Trojan-gen {Other}
Ikarus T3.1.1.45.0 2008.11.15 Trojan-Downloader.Win32.FraudLoad
K7AntiVirus 7.10.526 2008.11.15 Trojan-Downloader.Win32.FraudLoad.vdlc
Kaspersky 7.0.0.125 2008.11.15 Trojan-Downloader.Win32.FraudLoad.vdlc
McAfee 5434 2008.11.14 FakeAlert-AB
Microsoft 1.4104 2008.11.15 TrojanDownloader:Win32/Renos
NOD32 3615 2008.11.15 -
Norman 5.80.02 2008.11.14 W32/DLoader.KTQX
Panda 9.0.0.4 2008.11.15 Adware/Xpantivirus2008
PCTools 4.4.2.0 2008.11.15 -
Prevx1 V2 2008.11.15 -
Rising 21.03.42.00 2008.11.14 -
SecureWeb-Gateway 6.7.6 2008.11.14 Trojan.Dldr.FraudLoad.vdlc
Sophos 4.35.0 2008.11.15 Mal/Generic-A
Sunbelt 3.1.1801.2 2008.11.14 -
Symantec 10 2008.11.15 -
TheHacker 6.3.1.1.152 2008.11.13 -
TrendMicro 8.700.0.1004 2008.11.14 TROJ_FAKEAV.XR
VBA32 3.12.8.9 2008.11.14 -
ViRobot 2008.11.15.1470 2008.11.15 -
VirusBuster 4.5.11.0 2008.11.14 -
 
Additional information
File size: 163840 bytes
MD5…: 5bd224f0fa4fa6120186ff9bd6f7b874
SHA1..: fa7c5868cd788786086e84bce49405544344cd7b
SHA256: 78e2fe7e834721c9eca5171d3e4078e7f27d3f97d00aaf724ece51400038a95f
SHA512: 7ae2f1068c20e5f45ba660e048fb8fb814b8a67e8f5486b6de0a8f5e8cad400a
edd619f8805e861c91aae0925555a92aa4394dd225c62810ac6b84f5b4b394be
PEiD..: -
TrID..: File type identification
Win32 Executable Generic (42.3%)
Win32 Dynamic Link Library (generic) (37.6%)
Generic Win/DOS Executable (9.9%)
DOS Executable Generic (9.9%)
VXD Driver (0.1%)
PEInfo: PE Structure information( base data )
entrypointaddress.: 0×401167
timedatestamp…..: 0×45bb4551 (Sat Jan 27 12:28:01 2007)
machinetype…….: 0×14c (I386)( 8 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0×1000 0×5045 0×6000 0.69 37201dedc3c62b3f80091e4e2c12a76c
.rdata 0×7000 0×1012 0×2000 0.00 0829f71740aab1ab98b33eae21dee122
.data 0×9000 0×2c0efd 0×16000 6.10 9878f70f1e61fd935bbeb99d549a6a4c
.tls 0×2ca000 0×5f 0×1000 0.00 620f0b67a91f7f74151bc5be745b7110
.rdata 0×2cb000 0×418 0×1000 0.04 0fde2d8028c16bbcaa57889bf4353caf
.idata 0×2cc000 0×980 0×1000 3.45 e5ea0b80b0b55a2c73aee5c423e8956e
.reloc 0×2cd000 0×3a3 0×1000 0.00 620f0b67a91f7f74151bc5be745b7110
.rsrc 0×2ce000 0×4ffb 0×5000 4.66 2fa0c20dd8fbcf1837e630bc7d807913

( 5 imports )
> KERNEL32.DLL: DeleteFileA, GetCommandLineA, CopyFileW, CopyFileA, GetLastError, CreateProcessA, OpenFileMappingA, GetFileSize, WriteFile, OpenFile, GetConsoleMode, CopyFileExW, GetStdHandle, CreateDirectoryA, GetFileTime, ExitThread, GlobalFree, ReadFile, Sleep, GetCPInfo, FindAtomA, CreateThread
> USER32.DLL: InsertMenuA, GetDC, CopyImage, DrawTextA, GetFocus, GetMenu, DrawIconEx, AppendMenuW, CalcMenuBar, BlockInput, GetCursor, LoadCursorA, LoadMenuA, CopyRect, GetDlgItem, IsWindow
> ADVAPI32.DLL: RegOpenKeyW, RegOpenKeyA, RegReplaceKeyW, RegCreateKeyExA, RegQueryInfoKeyW, RegLoadKeyA, RegDeleteKeyA, RegOpenKeyExW, RegLoadKeyW, RegReplaceKeyA, RegEnumValueA, RegEnumKeyW, RegQueryValueA, RegCreateKeyExW, RegOpenKeyExA, RegCreateKeyW, RegEnumKeyA, RegEnumValueW, RegGetKeySecurity, RegEnumKeyExW
> ADVAPI32.DLL: RegOpenKeyA, RegLoadKeyA, RegQueryValueExA, RegQueryValueW, RegCreateKeyExA, RegReplaceKeyA, RegReplaceKeyW, RegEnumKeyW, RegCreateKeyExW, RegEnumKeyExA, RegQueryInfoKeyW, RegGetKeySecurity, RegOpenKeyW, RegDeleteKeyA, RegLoadKeyW, RegDeleteValueW, RegEnumKeyExW, RegEnumKeyA
> KERNEL32.DLL: GetComputerNameA, Sleep, GetStdHandle, GetCPInfo, DeleteFileA, ExitThread, GlobalFree, CopyFileA, DeleteFileW, CopyFileExA, CreateDirectoryA, GetFileSize, GetLastError, GetCommandLineA, OpenFileMappingA, GetConsoleMode, FindFirstFileA, SetLastError, OpenFile, CreateProcessA, CopyFileExW

( 0 exports )

Antivirus 2009

 

Host: softwareclicks2.com
IP: 64.86.17.44

Whois:

OrgName:    Teleglobe Inc.
OrgID:      GLBE
Address:    1441 Carrie-Derick
City:       Montreal
StateProv:  QC
PostalCode: H3C-4S9
Country:    CA

NetRange:   64.86.0.0 - 64.86.255.255
CIDR:       64.86.0.0/16
OriginAS:   AS6453
NetName:    TELEGLOBE
NetHandle:  NET-64-86-0-0-1
Parent:     NET-64-0-0-0-0
NetType:    Direct Allocation
NameServer: CASTOR.TELEGLOBE.NET
NameServer: POLLUX.TELEGLOBE.NET
Comment:    ADDRESSES WITHIN THIS BLOCK ARE NON-PORTABLE
RegDate:    2000-05-04
Updated:    2007-04-23

RAbuseHandle: ABUSE1643-ARIN
RAbuseName:   Abuse
RAbusePhone:  +1-514-868-7875

Host: total-antivirus-scan.com
IP: 64.86.17.44

Whois:

OrgName:    Teleglobe Inc.
OrgID:      GLBE
Address:    1441 Carrie-Derick
City:       Montreal
StateProv:  QC
PostalCode: H3C-4S9
Country:    CA

NetRange:   64.86.0.0 - 64.86.255.255
CIDR:       64.86.0.0/16
OriginAS:   AS6453
NetName:    TELEGLOBE
NetHandle:  NET-64-86-0-0-1
Parent:     NET-64-0-0-0-0
NetType:    Direct Allocation
NameServer: CASTOR.TELEGLOBE.NET
NameServer: POLLUX.TELEGLOBE.NET
Comment:    ADDRESSES WITHIN THIS BLOCK ARE NON-PORTABLE
RegDate:    2000-05-04
Updated:    2007-04-23

RAbuseHandle: ABUSE1643-ARIN
RAbuseName:   Abuse
RAbusePhone:  +1-514-868-7875

Host: premium-update.com
IP: 64.86.17.44

Whois:

OrgName:    Teleglobe Inc.
OrgID:      GLBE
Address:    1441 Carrie-Derick
City:       Montreal
StateProv:  QC
PostalCode: H3C-4S9
Country:    CA

NetRange:   64.86.0.0 - 64.86.255.255
CIDR:       64.86.0.0/16
OriginAS:   AS6453
NetName:    TELEGLOBE
NetHandle:  NET-64-86-0-0-1
Parent:     NET-64-0-0-0-0
NetType:    Direct Allocation
NameServer: CASTOR.TELEGLOBE.NET
NameServer: POLLUX.TELEGLOBE.NET
Comment:    ADDRESSES WITHIN THIS BLOCK ARE NON-PORTABLE
RegDate:    2000-05-04
Updated:    2007-04-23

RAbuseHandle: ABUSE1643-ARIN
RAbuseName:   Abuse
RAbusePhone:  +1-514-868-7875

Host: securedliveupdate.com
IP: 64.86.17.44

Whois:

OrgName:    Teleglobe Inc.
OrgID:      GLBE
Address:    1441 Carrie-Derick
City:       Montreal
StateProv:  QC
PostalCode: H3C-4S9
Country:    CA

NetRange:   64.86.0.0 - 64.86.255.255
CIDR:       64.86.0.0/16
OriginAS:   AS6453
NetName:    TELEGLOBE
NetHandle:  NET-64-86-0-0-1
Parent:     NET-64-0-0-0-0
NetType:    Direct Allocation
NameServer: CASTOR.TELEGLOBE.NET
NameServer: POLLUX.TELEGLOBE.NET
Comment:    ADDRESSES WITHIN THIS BLOCK ARE NON-PORTABLE
RegDate:    2000-05-04
Updated:    2007-04-23

RAbuseHandle: ABUSE1643-ARIN
RAbuseName:   Abuse
RAbusePhone:  +1-514-868-7875

Host: secureyourpayments.com
IP: 64.86.17.44

Whois of secureyourpayments.com:

Registrant:
   Valensia Holmes
   402 Office Park Drive
   Birmingham, Alabama 35223
   United States

   Registered through: GoDaddy.com, Inc. (http://www.godaddy.com)
   Domain Name: SECUREYOURPAYMENTS.COM
      Created on: 09-Sep-08
      Expires on: 09-Sep-09
      Last Updated on: 09-Sep-08

   Administrative Contact:
      Holmes, Valensia  ValensiaHolmesceo@googlemail.com
      402 Office Park Drive
      Birmingham, Alabama 35223
      United States
      (205) 830-9900      Fax –

   Technical Contact:
      Holmes, Valensia  ValensiaHolmesceo@googlemail.com
      402 Office Park Drive
      Birmingham, Alabama 35223
      United States
      (205) 830-9900      Fax –

  
Whois of 64.86.17.44:

OrgName:    Teleglobe Inc.
OrgID:      GLBE
Address:    1441 Carrie-Derick
City:       Montreal
StateProv:  QC
PostalCode: H3C-4S9
Country:    CA

NetRange:   64.86.0.0 - 64.86.255.255
CIDR:       64.86.0.0/16
OriginAS:   AS6453
NetName:    TELEGLOBE
NetHandle:  NET-64-86-0-0-1
Parent:     NET-64-0-0-0-0
NetType:    Direct Allocation
NameServer: CASTOR.TELEGLOBE.NET
NameServer: POLLUX.TELEGLOBE.NET
Comment:    ADDRESSES WITHIN THIS BLOCK ARE NON-PORTABLE
RegDate:    2000-05-04
Updated:    2007-04-23

RAbuseHandle: ABUSE1643-ARIN
RAbuseName:   Abuse
RAbusePhone:  +1-514-868-7875

Host: softwarebillingservice.com
IP: 63.219.177.214

Whois of softwarebillingservice.com

Registration Service Provided By: ERDOMAIN.COM
Contact: +49.3036741521
Website: http://www.erdomain.com

Domain Name: SOFTWAREBILLINGSERVICE.COM

Registrant:
    N/A
    Viktor Temchenko        (temchenkoviktor@googlemail.com)
    Pr. Geroev Tryda
    Kharkov
    Kharkiv Oblast,01001
    UA
    Tel. +380.936328480

Creation Date: 03-Nov-2008
Expiration Date: 03-Nov-2009

Whois of 63.219.177.214

OrgName:    Beyond The Network America, Inc.
OrgID:      BNA-42
Address:    450 Springpark PL
Address:    Suite 100
City:       Herdon
StateProv:  VA
PostalCode: 20170
Country:    US

 

Antivirus 2009

Rogue antivirus Antivirus 2009 from Pandora Software

Antivirus 2009

Windefender 2009 rogue antivirus and DNS changer

November 13, 2008 | Malware, Rogues

Windefender 2009  a rogue antivirus application. To remove that rogue application viruses and antispyware use Kaspersky antivirus - http://cleanthe.net/how-to-remove-virus/

Malware changing DNS to :

85.255.116.53
85.255.112.7

Whois:

netname:        UkrTeleGroup
descr:          UkrTeleGroup Ltd.
admin-c:        UA481-RIPE
tech-c:         UA481-RIPE
country:        UA
org:            ORG-UL25-RIPE
status:         ASSIGNED PI
mnt-by:         RIPE-NCC-HM-PI-MNT
mnt-lower:      RIPE-NCC-HM-PI-MNT
mnt-by:         UKRTELE-MNT
mnt-routes:     UKRTELE-MNT
mnt-domains:    UKRTELE-MNT
source:         RIPE # Filtered

 

Windefender2009

Windefender2009

 

File c-setup.exe received on 11.13.2008 15:32:29 (CET)
Antivirus Version Last Update Result
AhnLab-V3 2008.11.13.2 2008.11.13 -
AntiVir 7.9.0.31 2008.11.13 TR/BHO.Gen
Authentium 5.1.0.4 2008.11.13 -
Avast 4.8.1248.0 2008.11.12 -
AVG 8.0.0.199 2008.11.13 Downloader.Zlob_r.DQ
BitDefender 7.2 2008.11.13 Trojan.Dropper.SMN
CAT-QuickHeal 9.50 2008.11.12 -
ClamAV 0.94.1 2008.11.13 -
DrWeb 4.44.0.09170 2008.11.13 -
eSafe 7.0.17.0 2008.11.12 Suspicious File
eTrust-Vet 31.6.6204 2008.11.11 -
Ewido 4.0 2008.11.13 -
F-Prot 4.4.4.56 2008.11.12 -
F-Secure 8.0.14332.0 2008.11.13 Suspicious:W32/Malware!Gemini
Fortinet 3.117.0.0 2008.11.13 -
GData 19 2008.11.13 Trojan.Dropper.SMN
Ikarus T3.1.1.45.0 2008.11.13 -
K7AntiVirus 7.10.523 2008.11.12 -
Kaspersky 7.0.0.125 2008.11.13 -
McAfee 5432 2008.11.13 -
Microsoft 1.4104 2008.11.13 TrojanDownloader:Win32/Renos.DU
NOD32 3609 2008.11.13 a variant of Win32/Adware.IeDefender.NHN
Norman 5.80.02 2008.11.13 -
Panda 9.0.0.4 2008.11.12 Suspicious file
PCTools 4.4.2.0 2008.11.13 -
Prevx1 V2 2008.11.13 -
Rising 21.03.31.00 2008.11.13 -
SecureWeb-Gateway 6.7.6 2008.11.13 Trojan.BHO.Gen
Sophos 4.35.0 2008.11.13 -
Sunbelt 3.1.1785.2 2008.11.11 -
Symantec 10 2008.11.13 Downloader
TheHacker 6.3.1.1.151 2008.11.13 -
TrendMicro 8.700.0.1004 2008.11.13 PAK_Generic.001
VBA32 3.12.8.9 2008.11.12 -
ViRobot 2008.11.13.1466 2008.11.13 -
VirusBuster 4.5.11.0 2008.11.12 Trojan.Renos.Gen.16
 
Additional information
File size: 51207 bytes
MD5…: ebe6f36ae974d8b6be0b629afac74682
SHA1..: 52dca612d8bf577780aeaa1b8788dae867c09583
SHA256: f70f4d23a3ed712c427bfc2d380512f6a34e4d34cde1eba2224cab923a3b0fd6
SHA512: a90fb9d1ae6d8b6d18347f351f9ecd1645c08ed6fa312d2ff7104b3e453d7184
e97a6e2db180efeb7aa399b98021da0c62be642577e94ec606f9e83298a9df3d
PEiD..: UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser
TrID..: File type identification
UPX compressed Win32 Executable (39.5%)
Win32 EXE Yoda’s Crypter (34.3%)
Win32 Executable Generic (11.0%)
Win32 Dynamic Link Library (generic) (9.8%)
Generic Win/DOS Executable (2.5%)
PEInfo: PE Structure information( base data )
entrypointaddress.: 0×424bc0
timedatestamp…..: 0×491b5ccc (Wed Nov 12 22:46:36 2008)
machinetype…….: 0×14c (I386)( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
UPX0 0×1000 0×19000 0×0 0.00 d41d8cd98f00b204e9800998ecf8427e
UPX1 0×1a000 0xb000 0xae00 7.90 8530561432ff40aed0b00354e29fc2f7
.rsrc 0×25000 0×2000 0×1600 3.30 8cd6a8acc890e7440bbd21f9d01de4b5

( 3 imports )
> KERNEL32.DLL: LoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree, ExitProcess
> ADVAPI32.dll: RegCloseKey
> SHELL32.dll: ShellExecuteA

( 0 exports )

packers (F-Prot): UPX
packers (Kaspersky): PE_Patch.UPX, UPX

 
Windefender2009

Windefender2009

 

File WinDefender2009.exe received on 11.13.2008 15:33:08 (CET)
Antivirus Version Last Update Result
AhnLab-V3 2008.11.13.2 2008.11.13 -
AntiVir 7.9.0.31 2008.11.13 DR/Fraud.WinDefender.2009
Authentium 5.1.0.4 2008.11.13 -
Avast 4.8.1248.0 2008.11.12 -
AVG 8.0.0.199 2008.11.13 Generic3.ADNC
BitDefender 7.2 2008.11.13 -
CAT-QuickHeal 9.50 2008.11.12 -
ClamAV 0.94.1 2008.11.13 -
DrWeb 4.44.0.09170 2008.11.13 Trojan.Fakealert.origin
eSafe 7.0.17.0 2008.11.12 -
eTrust-Vet 31.6.6204 2008.11.11 -
Ewido 4.0 2008.11.13 -
F-Prot 4.4.4.56 2008.11.12 -
F-Secure 8.0.14332.0 2008.11.13 FraudTool.Win32.WinDefender.2009
Fortinet 3.117.0.0 2008.11.13 -
GData 19 2008.11.13 -
Ikarus T3.1.1.45.0 2008.11.13 Trojan.Win32.Delflob.I
K7AntiVirus 7.10.523 2008.11.12 -
Kaspersky 7.0.0.125 2008.11.13 not-a-virus:FraudTool.Win32.WinDefender.2009
McAfee 5432 2008.11.13 -
Microsoft 1.4104 2008.11.13 Trojan:Win32/Delflob.I
NOD32 3609 2008.11.13 probably a variant of Win32/Adware.IeDefender.NHA
Norman 5.80.02 2008.11.13 -
Panda 9.0.0.4 2008.11.12 -
PCTools 4.4.2.0 2008.11.13 -
Prevx1 V2 2008.11.13 -
Rising 21.03.31.00 2008.11.13 -
SecureWeb-Gateway 6.7.6 2008.11.13 Trojan.Dropper.Fraud.WinDefender.2009
Sophos 4.35.0 2008.11.13 IE Defender
Sunbelt 3.1.1785.2 2008.11.11 VIPRE.Suspicious
Symantec 10 2008.11.13 -
TheHacker 6.3.1.1.151 2008.11.13 -
TrendMicro 8.700.0.1004 2008.11.13 -
ViRobot 2008.11.13.1466 2008.11.13 -
VirusBuster 4.5.11.0 2008.11.12 -
 
Additional information
File size: 1726125 bytes
MD5…: 9f74ce5fb169ae4a78d1d3fca0c4768e
SHA1..: 31f7ef93e02394baa92f3f4aee84f907755580f8
SHA256: 1c53eb545a96cd85f68a0bd2b7b08d6b44e7f05a465f97a40bb2932e6b2da1a0
SHA512: 1542a404860a9b10248cd6bcf53b9e98eae73abd86c8983d23811da322ef3454
362053944c853930f667c3868d71311c693e7d893080364a41ddd7ba8340e727
PEiD..: -
TrID..: File type identification
Win32 Executable MS Visual C++ (generic) (65.2%)
Win32 Executable Generic (14.7%)
Win32 Dynamic Link Library (generic) (13.1%)
Generic Win/DOS Executable (3.4%)
DOS Executable Generic (3.4%)
PEInfo: PE Structure information( base data )
entrypointaddress.: 0×4030b4
timedatestamp…..: 0×4878f227 (Sat Jul 12 18:04:23 2008)
machinetype…….: 0×14c (I386)

( 5 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0×1000 0×57ec 0×5800 6.48 a06acff3c3236138ef0c89710413f34c
.rdata 0×7000 0×1190 0×1200 5.18 0f7b157b78f399340e80aa07581634eb
.data 0×9000 0×1af58 0×400 4.59 17047dc18ec7b67a9dd51dc161e64f03
.ndata 0×24000 0×9000 0×0 0.00 d41d8cd98f00b204e9800998ecf8427e
.rsrc 0×2d000 0×42c0 0×4400 5.83 2d51bf4ac683af918d43b3e1f3df9401

( 8 imports )
> KERNEL32.dll: CompareFileTime, SearchPathA, GetShortPathNameA, GetFullPathNameA, MoveFileA, SetCurrentDirectoryA, GetFileAttributesA, GetLastError, CreateDirectoryA, SetFileAttributesA, Sleep, GetTickCount, GetFileSize, GetModuleFileNameA, GetCurrentProcess, CopyFileA, ExitProcess, GetWindowsDirectoryA, SetFileTime, GetCommandLineA, SetErrorMode, LoadLibraryA, lstrcpynA, GetDiskFreeSpaceA, GlobalUnlock, GlobalLock, CreateThread, CreateProcessA, RemoveDirectoryA, CreateFileA, GetTempFileNameA, lstrlenA, lstrcatA, GetSystemDirectoryA, GetVersion, CloseHandle, lstrcmpiA, lstrcmpA, ExpandEnvironmentStringsA, GlobalFree, GlobalAlloc, WaitForSingleObject, GetExitCodeProcess, GetModuleHandleA, LoadLibraryExA, GetProcAddress, FreeLibrary, MultiByteToWideChar, WritePrivateProfileStringA, GetPrivateProfileStringA, WriteFile, ReadFile, MulDiv, SetFilePointer, FindClose, FindNextFileA, FindFirstFileA, DeleteFileA, GetTempPathA
> USER32.dll: EndDialog, ScreenToClient, GetWindowRect, EnableMenuItem, GetSystemMenu, SetClassLongA, IsWindowEnabled, SetWindowPos, GetSysColor, GetWindowLongA, SetCursor, LoadCursorA, CheckDlgButton, GetMessagePos, LoadBitmapA, CallWindowProcA, IsWindowVisible, CloseClipboard, SetClipboardData, EmptyClipboard, RegisterClassA, TrackPopupMenu, AppendMenuA, CreatePopupMenu, GetSystemMetrics, SetDlgItemTextA, GetDlgItemTextA, MessageBoxIndirectA, CharPrevA, DispatchMessageA, PeekMessageA, DestroyWindow, CreateDialogParamA, SetTimer, SetWindowTextA, PostQuitMessage, SetForegroundWindow, wsprintfA, SendMessageTimeoutA, FindWindowExA, SystemParametersInfoA, CreateWindowExA, GetClassInfoA, DialogBoxParamA, CharNextA, OpenClipboard, ExitWindowsEx, IsWindow, GetDlgItem, SetWindowLongA, LoadImageA, GetDC, EnableWindow, InvalidateRect, SendMessageA, DefWindowProcA, BeginPaint, GetClientRect, FillRect, DrawTextA, EndPaint, ShowWindow
> GDI32.dll: SetBkColor, GetDeviceCaps, DeleteObject, CreateBrushIndirect, CreateFontIndirectA, SetBkMode, SetTextColor, SelectObject
> SHELL32.dll: SHGetPathFromIDListA, SHBrowseForFolderA, SHGetFileInfoA, ShellExecuteA, SHFileOperationA, SHGetSpecialFolderLocation
> ADVAPI32.dll: RegQueryValueExA, RegSetValueExA, RegEnumKeyA, RegEnumValueA, RegOpenKeyExA, RegDeleteKeyA, RegDeleteValueA, RegCloseKey, RegCreateKeyExA
> COMCTL32.dll: ImageList_AddMasked, ImageList_Destroy, -, ImageList_Create
> ole32.dll: CoTaskMemFree, OleInitialize, OleUninitialize, CoCreateInstance
> VERSION.dll: GetFileVersionInfoSizeA, GetFileVersionInfoA, VerQueryValueA

( 0 exports )

 

 

Windefender2009

Host: megauplinkbindinstaller.com
IP: 91.203.92.99

Whois:

netname:        BASTION-NET
descr:          ISP UATelecom
country:        EU
org:            ORG-TG39-RIPE
admin-c:        ML7676-RIPE
tech-c:         UNm3-RIPE
status:         ASSIGNED PI
mnt-by:         UATELECOM-MNT
mnt-lower:      UATELECOM-MNT
mnt-routes:     UATELECOM-MNT
mnt-domains:    UATELECOM-MNT

Other sites:

1.  Megauplinkbindinstaller.com 
2.  Theupdatedownload.com 

Host: videofreeforonline.com
IP: 91.203.92.97

Whois:

netname:        BASTION-NET
descr:          ISP UATelecom
country:        EU
org:            ORG-TG39-RIPE
admin-c:        ML7676-RIPE
tech-c:         UNm3-RIPE
status:         ASSIGNED PI
mnt-by:         UATELECOM-MNT
mnt-lower:      UATELECOM-MNT
mnt-routes:     UATELECOM-MNT
mnt-domains:    UATELECOM-MNT

Other sites:

1.  Mybestmp3portal.com 
2.  Myprivatevideoarchive.com 
3.  Videofreeforonline.com 

Host: windefender-2009.com
IP: 200.63.45.55

Whois:

status:      reallocated
owner:       Ricardo Carreras
ownerid:     HN-RICA-LACNIC
responsible: Honduras Web
address:     P.O.Box: 1142 La Ceiba, #37 street., 1142, 37
address:     00000 - Tegucigalpa - TE
country:     HN
phone:       +504  9815-3645 []
owner-c:     RIC9
tech-c:      RIC9
abuse-c:     RIC9
created:     20080630
changed:     20080630
inetnum-up:  200.63.40/21

nic-hdl:     RIC9
person:      Ricardo Carreras

Host: windefender2009.com
IP: 200.63.45.55

Whois:

status:      reallocated
owner:       Ricardo Carreras
ownerid:     HN-RICA-LACNIC
responsible: Honduras Web
address:     P.O.Box: 1142 La Ceiba, #37 street., 1142, 37
address:     00000 - Tegucigalpa - TE
country:     HN
phone:       +504  9815-3645 []
owner-c:     RIC9
tech-c:      RIC9
abuse-c:     RIC9
created:     20080630
changed:     20080630
inetnum-up:  200.63.40/21

nic-hdl:     RIC9
person:      Ricardo Carreras

Windefender2009

Windefender2009

Antivirus Pro 2009 rogue antivirus application

November 11, 2008 | Malware, Rogues

Antivirus PRO 2009  a rogue antivirus application. To remove that rogue application viruses and antispyware use Kaspersky antivirus - http://cleanthe.net/how-to-remove-virus/

Antivirus Pro 2009

Antivirus Pro 2009

Antivirus Pro 2009

File zcodec.1073.exe received on 11.11.2008 19:24:57 (CET)
Antivirus Version Last Update Result
AhnLab-V3 2008.11.11.2 2008.11.11 -
AntiVir 7.9.0.31 2008.11.11 TR/Dldr.Agent.aopv.1
Authentium 5.1.0.4 2008.11.11 -
Avast 4.8.1248.0 2008.11.11 -
AVG 8.0.0.161 2008.11.11 -
BitDefender 7.2 2008.11.11 Trojan.Downloader.JLGV
CAT-QuickHeal 9.50 2008.11.11 -
ClamAV 0.94.1 2008.11.11 -
DrWeb 4.44.0.09170 2008.11.11 Trojan.DownLoad.12614
eSafe 7.0.17.0 2008.11.11 Suspicious File
eTrust-Vet 31.6.6203 2008.11.11 -
Ewido 4.0 2008.11.11 -
F-Prot 4.4.4.56 2008.11.11 -
F-Secure 8.0.14332.0 2008.11.11 Trojan-Downloader.Win32.Agent.aopv
Fortinet 3.117.0.0 2008.11.11 -
GData 19 2008.11.11 Trojan.Downloader.JLGV
Ikarus T3.1.1.45.0 2008.11.11 -
K7AntiVirus 7.10.522 2008.11.11 -
Kaspersky 7.0.0.125 2008.11.11 Trojan-Downloader.Win32.Agent.aopv
McAfee 5430 2008.11.10 -
Microsoft 1.4104 2008.11.11 TrojanDownloader:Win32/Renos.BAH
NOD32 3603 2008.11.11 -
Norman 5.80.02 2008.11.11 W32/Agent.JFWT
Panda 9.0.0.4 2008.11.10 -
PCTools 4.4.2.0 2008.11.11 -
Prevx1 V2 2008.11.11 Malware Downloader
Rising 21.03.12.00 2008.11.11 -
SecureWeb-Gateway 6.7.6 2008.11.11 Trojan.Dldr.Agent.aopv.1
Sophos 4.35.0 2008.11.11 -
Sunbelt 3.1.1785.2 2008.11.11 -
Symantec 10 2008.11.11 Downloader
TheHacker 6.3.1.1.147 2008.11.10 -
TrendMicro 8.700.0.1004 2008.11.11 Possible_DLDER
VBA32 3.12.8.9 2008.11.10 -
ViRobot 2008.11.11.1461 2008.11.11 Trojan.Win32.Downloader.55808.AS
VirusBuster 4.5.11.0 2008.11.11 -
 
Additional information
File size: 55808 bytes
MD5…: 86a8c4c834ef47c5974396b250f03ded
SHA1..: 2fb4352d7afcb8694b9670e1d2bc59296019638b
SHA256: 10fa14b397f86228d6c3446a33738ce9b0d08a525906b80a7c2e43d6f4ce775d
SHA512: f81691520c44189569287d572422fa1a4943710391528e55fb9a5b3c7e7b83f3
1ea35efdbf3a85f2748bc8fcc54a608d1cb2879a7fbb2234fed1ab531983f3b8
PEiD..: -
TrID..: File type identification
Win32 Executable Generic (42.3%)
Win32 Dynamic Link Library (generic) (37.6%)
Generic Win/DOS Executable (9.9%)
DOS Executable Generic (9.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
PEInfo: PE Structure information
Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=BD71A29D001427ADDA76007E4397A000C9DE7864
ThreatExpert info: http://www.threatexpert.com/report.aspx?md5=86a8c4c834ef47c5974396b250f03ded

Antivirus Pro 2009

File Install.exe received on 11.11.2008 19:25:24 (CET)
Antivirus Version Last Update Result
AhnLab-V3 2008.11.11.2 2008.11.11 Win-Trojan/Fakeav.9728
AntiVir 7.9.0.31 2008.11.11 SPR/Fraud.An.224075
Authentium 5.1.0.4 2008.11.11 -
Avast 4.8.1248.0 2008.11.11 Win32:Lighty-D
AVG 8.0.0.161 2008.11.11 Downloader.Agent.AOON
BitDefender 7.2 2008.11.11 -
CAT-QuickHeal 9.50 2008.11.11 (Suspicious) - DNAScan
ClamAV 0.94.1 2008.11.11 -
DrWeb 4.44.0.09170 2008.11.11 -
eSafe 7.0.17.0 2008.11.11 Suspicious File
eTrust-Vet 31.6.6203 2008.11.11 Win32/FakeAV.MF
Ewido 4.0 2008.11.11 -
F-Prot 4.4.4.56 2008.11.11 -
F-Secure 8.0.14332.0 2008.11.11 Rogue:W32/XPAntivirus.GJJ
Fortinet 3.117.0.0 2008.11.11 -
GData 19 2008.11.11 Win32:Lighty-D
Ikarus T3.1.1.45.0 2008.11.11 Trojan.Win32.FakePowav
K7AntiVirus 7.10.522 2008.11.11 -
Kaspersky 7.0.0.125 2008.11.11 -
McAfee 5430 2008.11.10 Generic FakeAlert.d
Microsoft 1.4104 2008.11.11 TrojanDownloader:Win32/FakeRean.gen!C
NOD32 3603 2008.11.11 -
Norman 5.80.02 2008.11.11 W32/Antivirus2008.UB
Panda 9.0.0.4 2008.11.10 Adware/AntivirusPro2009
PCTools 4.4.2.0 2008.11.11 -
Prevx1 V2 2008.11.11 Malicious Software
Rising 21.03.12.00 2008.11.11 -
SecureWeb-Gateway 6.7.6 2008.11.11 Riskware.Fraud.An.224075
Sophos 4.35.0 2008.11.11 Mal/EncPk-EQ
Sunbelt 3.1.1785.2 2008.11.11 VIPRE.Suspicious
Symantec 10 2008.11.11 XPAntivirus
TheHacker 6.3.1.1.147 2008.11.10 -
TrendMicro 8.700.0.1004 2008.11.11 -
VBA32 3.12.8.9 2008.11.10 -
ViRobot 2008.11.11.1461 2008.11.11 -
VirusBuster 4.5.11.0 2008.11.11 Trojan.FakeAlert.Gen!Pac.3
 
Additional information
File size: 125883 bytes
MD5…: ed04e6ae25983d3e0504c3c5e989f40d
SHA1..: 76f06b84908671544e2203f3a42d829e2d9fa45f
SHA256: 8a8107c9950659e65e83e0971629781ee32679590958c3f88a9f0c2a0ad2dc1d
SHA512: 9da02bf3fd3166d9c3b5bef25038c8000727b40296e9098eb576d205e3ba1611
d8c5adbc9c3c21d6765e49d60c90fb70909dc18851ad5beeb2b09e58d8207d2b
PEiD..: -
TrID..: File type identification
Win32 Executable Generic (42.3%)
Win32 Dynamic Link Library (generic) (37.6%)
Generic Win/DOS Executable (9.9%)
DOS Executable Generic (9.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
PEInfo: PE Structure information
Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=369D77BCBBC767C6EB08012DDDE82A0084807989

Antivirus Pro 2009

Host: newer-iporn-hub08.com
IP: 66.232.105.253

Whois:

OrgName:    NOC4Hosts Inc.
OrgID:      NOC4H
Address:    400 N Tampa St
Address:    #1025
City:       Tampa
StateProv:  FL
PostalCode: 33602
Country:    US

Host:  www.av-pro-2009.com
IP: 92.48.201.50

Whois:

netname:        NEWRACK-NL
descr:          NewRack.eu NL department
country:        NL
admin-c:        SVS148-RIPE
tech-c:                SVS148-RIPE
status:                ASSIGNED PA
mnt-by:                WEDARE-MNT
source:         RIPE # Filtered

person:         Sergey V. Smirnoff
address:        OOO “Ronetel”
address:        Lenina 129 o. 17
address:        Moscow
address:        Russia
phone:          +852 812 4838
fax-no:         +852 812 4838

Other sites:

1.  Av-pro-2009.com 
2.  Avpro2009.com 

Host: secure.soft-payments.com
IP: 92.48.201.52

Whois of secure.soft-payments.com:

Registrant Contact:
   Matthew Charles
   Matthew Charles
   +380.930772466 fax: +380.930772466
   30 Leicester Square
   London UK WC2H 7LA
   gb

Administrative Contact:
   Villi Mikoca
   +1.8821121128 fax: +1.8821121128
   3113 po box
   New York NY 10017
   us

Technical Contact:
   Villi Mikoca
   +1.8821121128 fax: +1.8821121128
   3113 po box
   New York NY 10017
   us

Billing Contact:
   Villi Mikoca
   +1.8821121128 fax: +1.8821121128
   3113 po box
   New York NY 10017
   us
  
Whois of 92.48.201.52:

netname:        NEWRACK-NL
descr:          NewRack.eu NL department
country:        NL
admin-c:        SVS148-RIPE
tech-c:                SVS148-RIPE
status:                ASSIGNED PA
mnt-by:                WEDARE-MNT
source:         RIPE # Filtered

person:         Sergey V. Smirnoff
address:        OOO “Ronetel”
address:        Lenina 129 o. 17
address:        Moscow
address:        Russia
phone:          +852 812 4838
fax-no:         +852 812 4838

 

Antivirus Pro 2009

Antivirus 2009 rogue antivirus application

November 11, 2008 | Malware, Rogues

Antivirus 2009  a rogue antivirus application. To remove that rogue application viruses and antispyware use Kaspersky antivirus - http://cleanthe.net/how-to-remove-virus/

Antivirus 2009

Antivirus 2009

File xcodec.135.exe received on 11.11.2008 13:57:09 (CET)
Antivirus Version Last Update Result
AhnLab-V3 2008.11.11.0 2008.11.10 -
AntiVir 7.9.0.29 2008.11.11 TR/Dldr.Agent.aopv
Authentium 5.1.0.4 2008.11.11 -
Avast 4.8.1248.0 2008.11.10 -
AVG 8.0.0.161 2008.11.11 -
BitDefender 7.2 2008.11.11 Trojan.Downloader.JLGV
CAT-QuickHeal 9.50 2008.11.11 -
ClamAV 0.94.1 2008.11.11 -
DrWeb 4.44.0.09170 2008.11.11 Trojan.DownLoad.12614
eSafe 7.0.17.0 2008.11.10 Suspicious File
eTrust-Vet 31.6.6202 2008.11.10 -
Ewido 4.0 2008.11.10 -
F-Prot 4.4.4.56 2008.11.10 -
F-Secure 8.0.14332.0 2008.11.11 Trojan-Downloader.Win32.Agent.aopv
Fortinet 3.117.0.0 2008.11.11 -
GData 19 2008.11.11 Trojan.Downloader.JLGV
Ikarus T3.1.1.45.0 2008.11.11 -
K7AntiVirus 7.10.521 2008.11.10 -
Kaspersky 7.0.0.125 2008.11.11 Trojan-Downloader.Win32.Agent.aopv
McAfee 5430 2008.11.10 -
Microsoft 1.4104 2008.11.11 TrojanDownloader:Win32/Renos.BAH
NOD32 3602 2008.11.11 -
Norman 5.80.02 2008.11.10 -
Panda 9.0.0.4 2008.11.10 -
PCTools 4.4.2.0 2008.11.10 -
Prevx1 V2 2008.11.11 Malware Downloader
Rising 21.03.12.00 2008.11.11 -
SecureWeb-Gateway 6.7.6 2008.11.11 Trojan.Dldr.Agent.aopv
Sophos 4.35.0 2008.11.11 -
Sunbelt 3.1.1785.2 2008.11.11 -
Symantec 10 2008.11.11 Downloader
TheHacker 6.3.1.1.147 2008.11.10 -
TrendMicro 8.700.0.1004 2008.11.11 Possible_DLDER
VBA32 None 2008.11.10 -
ViRobot 2008.11.11.1461 2008.11.11 Trojan.Win32.Downloader.55808.AS
VirusBuster 4.5.11.0 2008.11.10 -
 
Additional information
File size: 55808 bytes
MD5…: 5b7bedc0799a3982cb45092a4c83bea0
SHA1..: a50f1da1b08393d01dc46537e2fe7fbf45d5751d
SHA256: 823902dd438bfaaa762e41bf5f3d6110b0c4524d28bddeb31a35b742252bd9e4
SHA512: ae260e3834514f3659ec9155457d723bb1e55c8e7bb9486b094fd978e9a9c20f
9bad7a31f515c756d5b4392cb623fdc00e869ebed8db88bfae47d2c934bbd82f
PEiD..: -
TrID..: File type identification
Win32 Executable Generic (42.3%)
Win32 Dynamic Link Library (generic) (37.6%)
Generic Win/DOS Executable (9.9%)
DOS Executable Generic (9.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
PEInfo: PE Structure information
ThreatExpert info: http://www.threatexpert.com/report.aspx?md5=5b7bedc0799a3982cb45092a4c83bea0
Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=BD71A29D001427ADDA76007E4397A000C9DE7864

Antivirus 2009

File A9installer_77100102.exe received on 11.11.2008 19:23:39 (CET)
Antivirus Version Last Update Result
AhnLab-V3 2008.11.11.2 2008.11.11 -
AntiVir 7.9.0.31 2008.11.11 -
Authentium 5.1.0.4 2008.11.11 -
Avast 4.8.1248.0 2008.11.11 -
AVG 8.0.0.161 2008.11.11 -
BitDefender 7.2 2008.11.11 -
CAT-QuickHeal 9.50 2008.11.11 -
ClamAV 0.94.1 2008.11.11 -
DrWeb 4.44.0.09170 2008.11.11 -
eSafe 7.0.17.0 2008.11.11 -
eTrust-Vet 31.6.6203 2008.11.11 -
Ewido 4.0 2008.11.11 -
F-Prot 4.4.4.56 2008.11.11 -
F-Secure 8.0.14332.0 2008.11.11 -
Fortinet 3.117.0.0 2008.11.11 -
GData 19 2008.11.11 -
Ikarus T3.1.1.45.0 2008.11.11 -
K7AntiVirus 7.10.522 2008.11.11 -
Kaspersky 7.0.0.125 2008.11.11 -
McAfee 5430 2008.11.10 -
Microsoft 1.4104 2008.11.11 -
NOD32 3603 2008.11.11 -
Norman 5.80.02 2008.11.11 -
Panda 9.0.0.4 2008.11.10 -
PCTools 4.4.2.0 2008.11.11 -
Prevx1 V2 2008.11.11 -
Rising 21.03.12.00 2008.11.11 -
SecureWeb-Gateway 6.7.6 2008.11.11 -
Sophos 4.35.0 2008.11.11 -
Sunbelt 3.1.1785.2 2008.11.11 -
Symantec 10 2008.11.11 -
TheHacker 6.3.1.1.147 2008.11.10 -
TrendMicro 8.700.0.1004 2008.11.11 -
VBA32 3.12.8.9 2008.11.10 -
ViRobot 2008.11.11.1461 2008.11.11 -
VirusBuster 4.5.11.0 2008.11.11 -
 
Additional information
File size: 163840 bytes
MD5…: 0daff08fae0cb908a4e138579668283c
SHA1..: 713a85cd49d8045bec9ef867750eae48d43a5c9a
SHA256: fb172057c7e4d51c2fea163f78bf6be307865661d20767204e78db42ed0c3aa9
SHA512: 980389cbedb1343a246c7fd173740963d84cfbbd228d068873264b5eaf061bc3
8ee2a02a29faf4b211dbdcf3358b04d49bb64609750a88aeb16aedf3997b1968
PEiD..: -
TrID..: File type identification
Win32 Executable Generic (42.3%)
Win32 Dynamic Link Library (generic) (37.6%)
Generic Win/DOS Executable (9.9%)
DOS Executable Generic (9.9%)
VXD Driver (0.1%)
PEInfo: PE Structure information

 

Host: newer-pon-hub2009.com
IP: 74.50.117.88

Whois:

OrgName:    NOC4Hosts Inc.
OrgID:      NOC4H
Address:    400 N Tampa St
Address:    #1025
City:       Tampa
StateProv:  FL
PostalCode: 33602
Country:    US

Other sites:

1.  Celebs-on-video-08.net 
2.  E-softpoertals2008.net 
3.  E-softportals.net 
4.  Funsoft-enjoyportal.net 
5.  I-softportal08.net 
6.  Main-downloadportal.net 
7.  Main-softwaredownload.net 
8.  Muzdownload.com 
9.  New-porn-hub.net 
10.  New-porns-hub.net 
11.  Newest-porn-tube.net 
12.  Soft4enjoy2008.net 
13.  Soft4funportal.net 
14.  Newer-pon-hub2009.com 

Host: codecdownload.comp-softportal.net
IP: 74.50.117.88

Whois:

OrgName:    NOC4Hosts Inc.
OrgID:      NOC4H
Address:    400 N Tampa St
Address:    #1025
City:       Tampa
StateProv:  FL
PostalCode: 33602
Country:    US

Host: digipayments-soft.com
IP: 208.72.168.185

Whois:

OrgName:    McColo Corporation
OrgID:      MCCOL
Address:    64 East main st. box 275
City:       Newark
StateProv:  DE
PostalCode: 19715
Country:    US

Host: softwarebillingservice.com
IP: 63.219.177.214

Whois of softwarebillingservice.com

Registration Service Provided By: ERDOMAIN.COM
Contact: +49.3036741521
Website: http://www.erdomain.com

Domain Name: SOFTWAREBILLINGSERVICE.COM

Registrant:
    N/A
    Viktor Temchenko       
    Pr. Geroev Tryda
    Kharkov
    Kharkiv Oblast,01001
    UA
    Tel. +380.936328480
 
Whois of 63.219.177.214:

OrgName:    Beyond The Network America, Inc.
OrgID:      BNA-42
Address:    450 Springpark PL
Address:    Suite 100
City:       Herdon
StateProv:  VA
PostalCode: 20170
Country:    US

Pandora software

Antivirus 2009