clipskeeper.com

WHOISGUARD, INC.  (Proxy Registrant)

Domain Information

The domain clipskeeper.com is registered by proxy through ENOM, INC. and was originally registered in November of 2012. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Amsterdam, Noord-Holland within Netherlands which resides on the RIPE Network Coordination Centre network.
Remove Malware from clipskeeper.com - Powered by Reason Core Security
Registrar:
ENOM, INC.

Server location:
Noord-Holland, Netherlands (NL)

Create date:
Friday, November 23, 2012

Expires date:
Wednesday, November 23, 2016

Updated date:
Saturday, December 19, 2015

ASN:
AS39572 ADVANCEDHOSTERS-AS ADVANCEDHOSTERS LIMITED

Scanner detections:
Detections  (83% detected)

Scan engine
Details
Detections

Malwarebytes
PUP.Optional.Amonetize.A, PUP.Optional.Handy.A
83.33%

avast!
Win32:Adware-BJY [PUP], Win32:Amonetize-AM [PUP], Win32:Amonetize-BJ [PUP], Win32:Dropper-gen [Drp]
83.33%

Dr.Web
Adware.Downware.1575, Adware.Downware.2467, Adware.Downware.3925, Adware.Downware.1584
83.33%

ESET NOD32
Win32/Amonetize.AG (variant), Win32/Amonetize.AJ (variant), Win32/Amonetize.AS (variant), Win32/ActiveMonetizer
83.33%

Kingsoft AntiVirus
Win32.Troj.Generic.a.(kcloud)
66.67%

Qihoo 360 Security
Win32/Virus.Adware.47b, Win32/Trojan.Adware.37e, Win32/Virus.Adware.932, Win32/Trojan.Dropper.c9f
66.67%

McAfee Web Gateway
Artemis!8D3386F3ACE9, Artemis!52DE26D456C5, PUP-FBM!2C78E5FBC36C, BehavesLike.Win32.SoftDropper.fc
66.67%

Reason Heuristics
PUP.Installer.ShetefSolutionsConsulting1998.?, PUP.Installer.Amonetizeltd.a, Threat.Win.Reputation.IMP
50.00%

McAfee
Artemis!8D3386F3ACE9, Artemis!52DE26D456C5, PUP-FBM!2C78E5FBC36C
50.00%

Sophos
Amonetize
50.00%

Avira AntiVirus
ADWARE/Adware.Gen2
50.00%

AhnLab V3 Security
PUP/Win32.Amonetiz
50.00%

Rising Antivirus
PE:Malware.Adware!6.17D8, NS:AdWare.Script.VBS.StartPage.g!1579249
50.00%

NANO AntiVirus
Riskware.Win32.Downware.cyusqp, Riskware.Nsis.Yontoo.cwhuxq
50.00%

Trend Micro House Call
TROJ_GEN.F47V0303, TROJ_GEN.F47V0412
33.33%

The domain clipskeeper.com has been seen to resolve to the following IP address.

February 9, 2014

File downloads found at URLs served by clipskeeper.com.

8 / 68      (PUP)
http://clipskeeper.com/.../14177  (gotclip_setup.exe)

6 / 68      (PUP)
http://clipskeeper.com/.../14176  (gotclip_setup.exe)

18 / 68    (PUP)
http://clipskeeper.com/.../36990  (microsoft.office.professional__2309_il15470.exe)

13 / 68    (Adware)
http://clipskeeper.com/.../36990  (minecraft premium account gene downloader__3687_i400818195_il6490054.exe)

18 / 68    (Adware)
http://clipskeeper.com/.../36990  (setup__6666_i558241476_il1884594.exe)

2 / 68
http://clipskeeper.com/.../36990  (gotclip_setup.exe)

March 27, 2014

URL:
http://clipskeeper.com/

Google Analytics:
UA-23390261

Title:
“GotCLIP Downloader -”

Web server:
Apache/2.2.23 (Unix) PHP/5.2.17 (PHP/5.2.17)

Remove Malware from clipskeeper.com - Powered by Reason Core Security