Total Secure 2009 rogue antivirus application
Wednesday, October 22nd, 2008Total Secure 2009 is a fake - rogue antivirus. To remove that rogue application viruses and antispyware use Kaspersky antivirus - http://cleanthe.net/how-to-remove-virus/

| File MediaTubeCodec_ver1.812.0.exe received on 10.22.2008 15:31:16 (CET) | |||
| Antivirus | Version | Last Update | Result |
| AhnLab-V3 | 2008.10.22.0 | 2008.10.22 | - |
| AntiVir | 7.9.0.5 | 2008.10.22 | TR/Dldr.Zlob.aajg |
| Authentium | 5.1.0.4 | 2008.10.22 | - |
| Avast | 4.8.1248.0 | 2008.10.22 | - |
| AVG | 8.0.0.161 | 2008.10.22 | - |
| BitDefender | 7.2 | 2008.10.22 | - |
| CAT-QuickHeal | 9.50 | 2008.10.22 | - |
| ClamAV | 0.93.1 | 2008.10.22 | - |
| DrWeb | 4.44.0.09170 | 2008.10.22 | - |
| eSafe | 7.0.17.0 | 2008.10.19 | - |
| eTrust-Vet | 31.6.6162 | 2008.10.21 | - |
| Ewido | 4.0 | 2008.10.22 | - |
| F-Prot | 4.4.4.56 | 2008.10.22 | - |
| F-Secure | 8.0.14332.0 | 2008.10.22 | - |
| Fortinet | 3.113.0.0 | 2008.10.22 | - |
| GData | 19 | 2008.10.22 | - |
| Ikarus | T3.1.1.44.0 | 2008.10.22 | Trojan-Downloader.Zlob |
| K7AntiVirus | 7.10.501 | 2008.10.21 | - |
| Kaspersky | 7.0.0.125 | 2008.10.22 | - |
| McAfee | 5411 | 2008.10.22 | - |
| Microsoft | 1.4005 | 2008.10.22 | TrojanDownloader:Win32/Zlob.gen!CD |
| NOD32 | 3545 | 2008.10.22 | - |
| Norman | 5.80.02 | 2008.10.22 | - |
| Panda | 9.0.0.4 | 2008.10.22 | - |
| PCTools | 4.4.2.0 | 2008.10.22 | - |
| Prevx1 | V2 | 2008.10.22 | - |
| Rising | 20.67.22.00 | 2008.10.22 | - |
| SecureWeb-Gateway | 6.7.6 | 2008.10.22 | Trojan.Dldr.Zlob.aajg |
| Sophos | 4.34.0 | 2008.10.22 | - |
| Sunbelt | 3.1.1742.1 | 2008.10.21 | - |
| Symantec | 10 | 2008.10.22 | - |
| TheHacker | 6.3.1.0.123 | 2008.10.22 | - |
| TrendMicro | 8.700.0.1004 | 2008.10.22 | - |
| VBA32 | 3.12.8.8 | 2008.10.22 | suspected of Win32.Trojan-Downloader |
| ViRobot | 2008.10.22.1432 | 2008.10.22 | - |
| VirusBuster | 4.5.11.0 | 2008.10.22 | - |
| Additional information | |||
| File size: 77824 bytes | |||
| MD5…: c1202919430900fd93e48dd6fab11cd6 | |||
| SHA1..: 832d6fc07e7d45c3e89d33d04667f651a472ec5d | |||
| SHA256: ae993034e5fcdb5839639746f5c6fd59f285e1a0e6b90a014deb0408901e7c96 | |||
| SHA512: a387584e9ba4db719800462d525c86b5ca4183eae74c7e0d1353977844372c63 3524dc2caf0c0b5605763de593e89952253fc2bfcfd537857da8731e1f2ce460 |
|||
| PEiD..: - | |||
| TrID..: File type identification Win32 Executable MS Visual C++ (generic) (65.2%) Win32 Executable Generic (14.7%) Win32 Dynamic Link Library (generic) (13.1%) Generic Win/DOS Executable (3.4%) DOS Executable Generic (3.4%) |
|||
| PEInfo: PE Structure information
( base data ) ( 4 sections ) ( 1 imports ) ( 0 exports ) |
|||


Host: moviesportal2008xxx.com
IP: 72.232.183.154
Whois:
OrgName: Layered Technologies, Inc.
OrgID: LAYER-3
Address: 5085 W Park Blvd
Address: Suite 700
City: Plano
StateProv: TX
PostalCode: 75093
Country: US
Other sites distributing rogue antivirus Total secure 2009:
1. Funnyportal2008p.com
2. Movieportal2008q.com
3. Mp3portal2008p.com
4. Softportal2008p.com
5. Starsportal2008p.com
6. Funnyportal2008xxx.com
7. Funnyportal2008yyy.com
8. Moviesportal2008eee.com
9. Moviesportal2008xxx.com
10. Moviesportal2008yyy.com
11. Moviesportal2008zzz.com
12. Mp3portal2008xxx.com
13. Mp3portal2008yyy.com
14. Softportal2008xxx.com
15. Softportal2008yyy.com
16. Starsportal2008xxx.com
17. Starsportal2008yyy.com
Host: softwaredownload2008hq.com
IP: 78.157.143.250
Whois:
netname: VDHOST
descr: VdHost Ltd.
descr:
country: LV
admin-c: AV2990-RIPE
tech-c: UNHM-RIPE
status: ASSIGNED PA
mnt-by: UN-MNT
source: RIPE # Filteredrole: UltraNet Hostmaster
address: UltraNet SIA
Aizkraukles 23
Riga, LV-1006
Latvia
phone: +371 67543003
fax-no: +371 67594435
Other sites distributing rogue antivirus Total secure 2009:
1. Softdownload2008nm.com
2. Softdownload2008p.com
3. Softdownoad2008name.com
4. Softload2008cx.com
5. Softwaredownload2008gs.com
6. Softwaredownload2008gt.com
7. Softwaredownload2008hq.com
8. Softwaredownload2008hs.com
9. Softwaredownload2008rs.com
10. Softwaredownload2008sq.com
11. Softwaredownload2008st.com
12. Softwaredownload2008tq.com
Host: total-secure2009.com
IP: 200.63.45.55
Whois:
inetnum: 200.63.45/24
status: reallocated
owner: Ricardo Carreras
ownerid: HN-RICA-LACNIC
responsible: Honduras Web
address: P.O.Box: 1142 La Ceiba, #37 street., 1142, 37
address: 00000 - Tegucigalpa - TE
country: HN
phone: +504 9815-3645 []
owner-c: RIC9
tech-c: RIC9
abuse-c: RIC9
created: 20080630
changed: 20080630
inetnum-up: 200.63.40/21
Other sites distributing rogue antivirus Total secure 2009:
1. Total-secure2009.com
2. Windefender-2009.com
Host: viacodecright—2.com
IP: 77.91.227.179
Whois:
person: Pavel Malinkovich
address: Tevosyana 40a-89
address: Electrostal, Moscow Region
address: Russia
phone: +7 495 5434485
abuse-mailbox: abuse@netplace.ru
nic-hdl: PM946-RIPE
source: RIPE # Filtered
Other sites distributing rogue antivirus Total secure 2009:
1. Codecadult23df18.com
2. Hot-sextubedriver2.com
3. Sextubecodec023dfs41.com
4. Viacodecright—2.com
Host: megauplinkbindinstaller.com
IP: 91.203.92.99
Whois:
netname: BASTION-NET
descr: ISP UATelecom
country: EU
org: ORG-TG39-RIPE
admin-c: ML7676-RIPE
tech-c: UNm3-RIPE
status: ASSIGNED PI
mnt-by: UATELECOM-MNT
mnt-lower: UATELECOM-MNT
mnt-routes: UATELECOM-MNT
mnt-domains: UATELECOM-MNT
Other sites distributing rogue antivirus Total secure 2009:
1. Megauplinkbindinstaller.com
2. Theupdatedownload.com
Host: onsafepro—2008.com
IP: 91.203.92.25
Whois:
netname: BASTION-NET
descr: ISP UATelecom
country: EU
org: ORG-TG39-RIPE
admin-c: ML7676-RIPE
tech-c: UNm3-RIPE
status: ASSIGNED PI
mnt-by: UATELECOM-MNT
mnt-lower: UATELECOM-MNT
mnt-routes: UATELECOM-MNT
mnt-domains: UATELECOM-MNT
Other sites distributing rogue antivirus Total secure 2009:
1. Directnameservice—2008.com
2. Onsafepro—2008.com
3. S-avirus.com
4. Viruswebprotect—2008.com
Host: secure.intro-pay.com
IP: 216.40.219.141
Whois:
OrgName: ThePlanet.com Internet Services, Inc.
OrgID: TPCM
Address: 315 Capitol
Address: Suite 205
City: Houston
StateProv: TX
PostalCode: 77002
Country: US
Other sites selling rogue antivirus Total secure 2009:
1. Ds-pay.com
2. Intro-pay.com
3. Ormondsystems.com
Host: protect.trustedantivirus.com
IP: 93.190.139.221
Whois:
netname: WORLDSTREAM
descr: WorldStream IPv4.4
country: NL
admin-c: WS1670-RIPE
tech-c: WS1670-RIPE
status: ASSIGNED PA
mnt-by: MNT-WORLDSTREAM
mnt-by: KABELFOON-MNT
source: RIPE # Filteredrole: WORLDSTREAM DBM
address: Honderdland 111F
address: 2676LT Maasdijk
phone: +31174712117
fax-no: +31174512310
Other sites:
1. Gomyhit.com
2. Gomyron.com
3. Rdrmngr.com
4. Sadafaha.com
5. Vmaff.com
Host: intervarioclick.com
IP: 76.74.249.30
Whois:
OrgName: Peer 1 Network Inc.
OrgID: PER1
Address: 75 Broad Street
Address: 2nd Floor
City: New York
StateProv: NY
PostalCode: 10004
Country: USOrgName: Peer 1 Network Inc.
OrgID: PER1
Address: 75 Broad Street
Address: 2nd Floor
City: New York
StateProv: NY
PostalCode: 10004
Country: US
Other sites:
1. Ad2cash.net
2. Ad2profit.com
3. Adcomatoz.com
4. Adgurman.com
5. Adhokuspokus.com
6. Adnetserver.com
7. Adredired.com
8. Adverdaemon.com
9. Adverlounge.com
10. Adzyclon.com
11. Astalaprofit.com
12. B2adz.com
13. Beststatsever.com
14. Bizadsonline.net
15. Bizadverts.com
16. Bizmarketads.com
17. Blessedads.com
18. Brandmarketads.com
19. Clickadnet.net
20. Friedads.com
21. Glorymarkets.com
22. Greatad.net
23. Hostadserve.com
24. Iddqdmarketing.com
25. Intervarioclick.com
26. Invulnerableads.com
27. Luckyadcoin.com
28. Luckyadsols.com
29. Moneycometrue.com
30. Mythmarketing.com
31. Popadprovider.com
32. Prevedmarketing.com
33. Rocktheads.com
34. Sharpadverts.com
35. Shivanetworking.com
36. Statisticsmanager.com
37. Statsreportserver.com
38. Waytotheprofit.com
39. Widestatsnow.com





























