dl2.iq4download.com

REACTIVATION PERIOD

Domain Information

The domain dl2.iq4download.com registered by REACTIVATION PERIOD was initially registered in April of 2011 through ENOM, INC.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dulles, Virginia within the United States which resides on the Limelight Networks, Inc. network.
Remove Malware from dl2.iq4download.com - Powered by Reason Core Security
Registrar:
ENOM, INC.

Server location:
Virginia, United States (US)

Create date:
Wednesday, April 27, 2011

Expires date:
Monday, April 27, 2015

Updated date:
Tuesday, June 09, 2015

ASN:
AS22822 LLNW-AS Limelight Networks, INC. proxy AS object

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.W3i.J, PUP.Installer.InstallX.J, PUP.Installer.W3i.K, PUP.Installer.W3i.H, PUP.Installer.W3i.S, PUP.Installer.InstallX.N, PUP.InstallX.Installer, PUP.InstallX.W3i.Installer (M)
100.00%

Dr.Web
Adware.W3i.4, Adware.W3i.32, Adware.W3i.9, Adware.Downware.12
88.89%

Malwarebytes
PUP.Optional.InstallIQ, PUP.Optional.InstallIQ.A
77.78%

VIPRE Antivirus
InstallIQ Installer, Trojan.Win32.Generic
77.78%

Avira AntiVirus
APPL/InstallIQ.Gen5
77.78%

ESET NOD32
Win32/InstallIQ (variant)
77.78%

Trend Micro House Call
TROJ_GEN.F47V0404, TROJ_GEN.USA27HO, ADW_INSTALLQ, TROJ_GEN.R00UH0AJP13, TROJ_GEN.R00UH01GC13, TROJ_GEN.F47V0917, TROJ_GEN.R047H0AJL13
77.78%

Rising Antivirus
PE:PUF.InstallIQ!1.9E4F, PE:Trojan.Win32.Generic.14A41BA7!346299303
66.67%

Fortinet FortiGate
Adware/InstallIQ, W32/FirseriaInstaller.A
66.67%

Sophos
InstallQ
66.67%

McAfee
Artemis!FBBB700F3F06, Artemis!71FE634C52B1, Artemis!614A23E882C3, Artemis!9C0671439D2B, Artemis!BA96BC364600, Artemis!D195ED596249, Artemis!62FA1B508049
61.11%

McAfee Web Gateway
Artemis!FBBB700F3F06, Artemis!71FE634C52B1, Artemis!614A23E882C3, Artemis!9C0671439D2B, Artemis!BA96BC364600, Artemis!D195ED596249
61.11%

K7 AntiVirus
Unwanted-Program
55.56%

K7 Gateway Antivirus
Unwanted-Program
55.56%

Baidu Antivirus
Trojan.Win32.Agent, Trojan.Win32.InstallIQ
50.00%

The domain dl2.iq4download.com has been seen to resolve to the following 5 IP addresses.

September 2, 2014

April 11, 2014

April 11, 2014

cdn-208-111-160-6.iad.llnw.net
February 20, 2014

cdn-208-111-161-254.iad.llnw.net
February 20, 2014

File downloads found at URLs served by dl2.iq4download.com.

11 / 68    (Adware)
http://dl2.iq4download.com/lm/.../7zipap_718.exe  (80db7972d6c4d3d996d4b219000ec6e1)

16 / 68    (Adware)
http://dl2.iq4download.com/lm/.../VLC_968.exe  (71fe634c52b1dd4d846070dfdea43ab9)

26 / 68    (Adware)
http://dl2.iq4download.com/lm/.../frzfonts.exe  (815b78850d1a2425e6af49c67a2fd6f8)

1 / 68      (Adware)

30 / 68    (Adware)

1 / 68      (Adware)
http://dl2.iq4download.com/lm/.../7zipap_718.exe  (23f4a173ccda8b842540deb25fc92d3a)

30 / 68    (Adware)
http://dl2.iq4download.com/lm/.../bitzipper_513.exe  (c7624ce1143ea24e0b531a00bd4ac376)

14 / 68    (Adware)
http://dl2.iq4download.com/lm/.../7zipap_718.exe  (0fd65eb1d6147b7bf4c7032b107e19ed)

17 / 68    (Adware)

15 / 68    (Adware)
http://dl2.iq4download.com/lm/.../jenkatarcade.exe  (d195ed5962494f5ee03a9cbdd97afc69)

12 / 68    (Adware)
http://dl2.iq4download.com/lm/.../intunemp3.exe  (50020f6374c431780fb4eeea9e8e2df0)

14 / 68    (Adware)

27 / 68    (Adware)
http://dl2.iq4download.com/lm/.../coretemp_1236.exe  (9c0671439d2bd411e3f1c33972aad991)

2 / 68      (Adware)
http://dl2.iq4download.com/lm/.../gimpts_729.exe  (d6718305aacc0f1d462c8d7ae4c333e4)

26 / 68    (Adware)
http://dl2.iq4download.com/lm/.../freefileviewer_730.exe  (614a23e882c3b31edec791c047607c72)

17 / 68    (Adware)

17 / 68    (Adware)

2 / 68      (Adware)
http://dl2.iq4download.com/lm/.../ac3filter.exe  (e38cc41f873a6df9947cdc72ccc39068)

The following 29 files have been seen to comunicate with dl2.iq4download.com in live environments.

 
Latest 20 of 44 files

Remove Malware from dl2.iq4download.com - Powered by Reason Core Security