The domain dll512.retailfile.biz registered by Whois Privacy Corp. was initially registered in September of 2014 through INTERNET.BS CORP.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Chicago, Illinois within the United States which resides on the FDCservers.net network.
Registrant:
Whois Privacy Corp.
Registrar:
INTERNET.BS CORP.
Server location:
Illinois, United States (US)
Create date:
Monday, September 15, 2014
Expires date:
Monday, September 14, 2015
Updated date:
Monday, September 15, 2014
ASN:
AS6461 ABOVENET - Abovenet Communications, Inc,US
Scanner detections:
Detections (100% detected)
Scan engine
Details
Detections
Reason Heuristics
PUP.Installer.ViaAdvertisingGroupLimited.j, PUP.Installer.ViaAdvertisingGroupLimited.o, PUP.Via Advertising.Bundler, PUP.Via Advertising.ViaAdvertisingGroup.Bundler (M), PUP.Via Advertising.ViaAdver.Bundler (M), PUP.Via Advertising (M)
100.00%
avast!
Win32:Downloader-UEO [PUP]
30.77%
VIPRE Antivirus
Threat.4758264
30.77%
Dr.Web
Adware.Downware.8126, Threat.Undefined, Adware.Downware.8715, Adware.Downware.10330
30.77%
Avira AntiVirus
TR/EDownload.J.2, APPL/Downloader.Gen8, APPL/Downloader.Gen4, PUA/EDownloader.Gen4
30.77%
ESET NOD32
Win32/ExpressDownloader.J potentially unwanted application, Win32/ExpressDownloader.K potentially unwanted application
23.08%
Malwarebytes
PUP.Optional.YourFileDown, PUP.Optional.Downloader
23.08%
AVG
Adware BundleApp_r, Adware Generic_r.AFD
15.38%
K7 AntiVirus
Adware , Unwanted-Program
15.38%
herdProtect (fuzzy)
a variant of fee845b9f00d040e30d21a245b2d054ae545c82a
7.69%
IKARUS anti.virus
PUA.Expressdownloader
7.69%
NANO AntiVirus
Riskware.Win32.Downware.deefau
7.69%
Agnitum Outpost
Riskware.Agent
7.69%
Baidu Antivirus
PUA.Win32.ExpressDownloader
7.69%
Kaspersky
HEUR:Trojan.Win32.Generic
7.69%
The domain dll512.retailfile.biz has been seen to resolve to the following IP address.
File downloads found at URLs served by dll512.retailfile.biz.
Related Domains