ct3297964.ourtoolbar.com

ClientConnect LTD

Domain Information

The domain ct3297964.ourtoolbar.com registered by ClientConnect LTD was initially registered in June of 2005 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in San Mateo, California within the United States which resides on the Conduit USA, Inc. network.
Remove Malware from ct3297964.ourtoolbar.com - Powered by Reason Core Security
Registrar:
GODADDY.COM, LLC

Server location:
California, United States (US)

Create date:
Wednesday, June 22, 2005

Expires date:
Monday, June 22, 2015

Updated date:
Thursday, December 12, 2013

ASN:
AS56473 CONDUIT-NL Conduit Connect B.V.

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.4323.Conduit.V, PUP.4218.Conduit.V
100.00%

Dr.Web
Adware.Conduit.6, Adware.BGuard.15
66.67%

Malwarebytes
PUP.Optional.Conduit.A
33.33%

NANO AntiVirus
Riskware.Win32.BGuard.csnycu
33.33%

VIPRE Antivirus
Conduit
33.33%

Kingsoft AntiVirus
Win32.HeurC.KVM099.a.(kcloud)
33.33%

ESET NOD32
Win32/Conduit.SearchProtect
33.33%

Panda Antivirus
PUP/Conduit.A
33.33%

The domain ct3297964.ourtoolbar.com has been seen to resolve to the following IP address.

May 1, 2014

File downloads found at URLs served by ct3297964.ourtoolbar.com.

1 / 68      (PUP)
http://ct3297964.ourtoolbar.com/.../  (begin_download_flv_b2.exe)

1 / 68      (PUP)
http://ct3297964.ourtoolbar.com/exe  (begin_download_flv_b2.exe)

8 / 68      (PUP)
http://ct3297964.ourtoolbar.com/.../  (begin_download_flv_b2.exe)

8 / 68      (PUP)
http://ct3297964.ourtoolbar.com/exe  (begin_download_flv_b2.exe)

2 / 68      (PUP)
http://ct3297964.ourtoolbar.com/.../  (begin_download_flv_b2.exe)

2 / 68      (PUP)
http://ct3297964.ourtoolbar.com/exe  (begin_download_flv_b2.exe)

URL:
http://ct3297964.ourtoolbar.com/

Google Analytics:
UA-46962615

Title:
“Begin-download FLV B2 Toolbar Download”

SSL certificate subject:
CN=*.ourtoolbar.com, OU=IT, O=Conduit LTD, L=Ness-Ziona, S=Israel, C=IL

SSL certificate issuer:
CN=VeriSign Class 3 Secure Server CA - G3, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Web server:
Microsoft-IIS/7.5 (ASP.NET) (Version: 2.0.50727)

Remove Malware from ct3297964.ourtoolbar.com - Powered by Reason Core Security