checksoft2upgrade.checkupdatenow.com
Privacy Protection Service INC d/b/a PrivacyProtect.org (Proxy Registrant)
Domain Information
The domain checksoft2upgrade.checkupdatenow.com is registered by proxy through REGISTRAR OF DOMAIN NAMES REG.RU LLC and was originally registered in January of 2015. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Montreal, Quebec within Canada which resides on the OVH Hosting, Inc. network.
Registrant:
Privacy Protection Service INC d/b/a PrivacyProtect.org
Registrar:
REGISTRAR OF DOMAIN NAMES REG.RU LLC
Server location:
Quebec, Canada (CA)
Create date:
Friday, January 30, 2015
Expires date:
Saturday, January 30, 2016
Updated date:
Friday, February 13, 2015
Scanner detections:
Detections (100% detected)
Scan engine
Details
Detections
Reason Heuristics
PUP.ProfitServis.OOOPREMERSERVIS.Bundler (M), PUP.ProfitServis.OOOPREME.Bundler (M), PUP.Coinis.installCore.Installer (M)
100.00%
Dr.Web
Trojan.InstallCore.56
20.00%
K7 AntiVirus
Riskware
20.00%
Avira AntiVirus
ADWARE/InstallCore.Gen
20.00%
ESET NOD32
Win32/InstallCore.WV potentially unwanted (variant)
20.00%
avast!
Rootkit-gen [Rtk]
20.00%
VIPRE Antivirus
Trojan.Win32.Generic
20.00%
F-Secure
Adware.SwiftBrowse.CR
20.00%
NANO AntiVirus
Riskware.Win32.InstallCore.dotkhj
20.00%
Agnitum Outpost
PUA.InstallCore
20.00%
Bkav FE
W32.HfsAdware
20.00%
Comodo Security
Application.Win32.InstallCore.DQR
20.00%
AhnLab V3 Security
PUP/Win32.InstallCore
20.00%
herdProtect (fuzzy)
a variant of d751126e87739e77149e7ae78cfabd1b1d546e6b
20.00%
The domain checksoft2upgrade.checkupdatenow.com has been seen to resolve to the following IP address.
ns513839.ip-167-114-156.net
May 19, 2016
File downloads found at URLs served by checksoft2upgrade.checkupdatenow.com.
The following 36 files have been seen to comunicate with checksoft2upgrade.checkupdatenow.com in live environments.