regconvoy.paretologic.revenuewire.net

REVENUEWIRE INC

Domain Information

This is the distribution delivery network for ParetoLogic software (PC optimization products including ParetoLogic RegCure, ParetoLogic FileCure and XoftSpy AntiVirus) through the RevenueWire affiliate/ecommerce program. The domain regconvoy.paretologic.revenuewire.net registered by REVENUEWIRE INC was initially registered in September of 2003 through ENOM, INC.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Victoria, British Columbia within Canada.
Registrar:
ENOM, INC.

Server location:
British Columbia, Canada (CA)

Create date:
Monday, September 8, 2003

Expires date:
Thursday, September 8, 2016

Updated date:
Tuesday, August 18, 2015

ASN:
AS6539 GT-BELL - Bell Canada

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.ParetoLogic.Optional.Installer.Meta (L), PUP.ParetoLogic.Optional (L)
92.86%

Dr.Web
riskware program Program.Unwanted.686, Trojan.Inject1.28681
14.29%

F-Secure
Gen:Adware.BrowseFox.1, Worm.Generic.377772
14.29%

Trend Micro House Call
Suspicious_GEN.F47V1122
7.14%

Vba32 AntiVirus
Malware-Cryptor.Win32.0073
7.14%

VIPRE Antivirus
Threat.4775899
7.14%

F-Prot
W32/Renamer.A.gen
7.14%

ESET NOD32
Win32/Delf.NRJ worm
7.14%

Microsoft Security Essentials
Threat.Undefined
7.14%

avast!
Win32:Agent-AODJ [Trj]
7.14%

AVG
Worm/Delf.KHX
7.14%

McAfee
Virus.W32/Gnamer
7.14%

Kaspersky
Virus.Win32.Renamer
7.14%

Norman
Worm.Generic.377772
7.14%

The domain regconvoy.paretologic.revenuewire.net has been seen to resolve to the following 4 IP addresses.

199.83.132.38.ip.incapdns.net
August 12, 2015

199.83.132.231.ip.incapdns.net
October 20, 2014

199.83.128.157.ip.incapdns.net
May 30, 2014

downloads.safecart.com
January 4, 2014

File downloads found at URLs served by regconvoy.paretologic.revenuewire.net.

1 / 68      (PUP)
http://regconvoy.paretologic.revenuewire.net/regcure-pro/.../  (regcureprosetup_f4d2af76-1288-49d7-8c1c-750ea2f7035f_.exe)

1 / 68      (PUP)
http://regconvoy.paretologic.revenuewire.net/regcure-pro/.../  (regcureprosetup_c6d504e8-ef69-4b66-8f2b-6066a23d15e6_.exe)

11 / 68    (Malware)
http://regconvoy.paretologic.revenuewire.net/regcure-pro/.../  (regcureprosetup_34bfc6d0-a2d7-4504-9362-075e5d1ec4f3_.exe)

1 / 68      (PUP)
http://regconvoy.paretologic.revenuewire.net/regcure-pro/.../  (regcureprosetup_154cf9a5-1190-4170-8ebc-078a0e41e697_.exe)

3 / 68      (PUP)
http://regconvoy.paretologic.revenuewire.net/pcha/.../  (paretologic pc health advisor.exe)

1 / 68      (PUP)

1 / 68      (PUP)

3 / 68      (PUP)
http://regconvoy.paretologic.revenuewire.net/regcure-pro/.../  (regcureprosetup_edcdfb75-9201-4924-b750-0fd0009942d1_.exe)

1 / 68      (PUP)
http://regconvoy.paretologic.revenuewire.net/regcure-pro/.../  (regcureprosetup_52559eaf-95c8-44eb-99f6-c27a0c09c080_.exe)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)