dl2.iq9download.com

InstallX, LLC

Domain Information

The domain dl2.iq9download.com registered by NATIVEX HOLDINGS, LLC was initially registered in April of 2012 through ENOM, INC.. This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in Dulles, Virginia within the United States which resides on the Limelight Networks, Inc. network. The domain is associated with the publisher InstallX, LLC who is located in Sartell, Minnesota in the United States.
Remove Malware from dl2.iq9download.com - Powered by Reason Core Security
Registrar:
ENOM, INC.

Server location:
Virginia, United States (US)

Create date:
Monday, April 16, 2012

Expires date:
Saturday, April 16, 2016

Updated date:
Monday, April 20, 2015

ASN:
AS22822 LLNW-AS Limelight Networks, INC. proxy AS object

Root domain:

Scanner detections:
Detections  (89% detected)

Scan engine
Details
Detections

Avira AntiVirus
W32/Sality.AT, APPL/InstallIQ.Gen5, Adware/InstallIQ.N
100.00%

Dr.Web
Win32.Sector.21, Adware.W3i.32
100.00%

Malwarebytes
PUP.Optional.InstallIQ, PUP.PlayPickle
88.89%

Trend Micro House Call
TROJ_GEN.F47V1128, TROJ_GEN.F47V0815, TROJ_GEN.F47V1024, TROJ_GEN.F47V1102, TROJ_GEN.F47V1111, TROJ_GEN.F47V1016
88.89%

Sophos
InstallQ
88.89%

Comodo Security
Application.Win32.InstallIQ.B
88.89%

VIPRE Antivirus
InstallIQ Installer
88.89%

ESET NOD32
Win32/InstallIQ (variant)
88.89%

Reason Heuristics
PUP.Installer.InstallX.J, PUP.Installer.InstallX.T, PUP.Installer.InstallX.q, PUP.Installer.InstallX.Q, PUP.Installer.InstallX.R
88.89%

Bkav FE
W32.Clod53c.Trojan, W32.Clodac9.Trojan, W32.Clod405.Trojan, W32.Clod1fe.Trojan, W32.Clod4fe.Trojan, W32.Clodf6a.Trojan
77.78%

K7 Gateway Antivirus
Unwanted-Program , Riskware
77.78%

K7 AntiVirus
Unwanted-Program , Riskware
77.78%

McAfee
Artemis!553CD710BF51, Artemis!A34F9AC02DB1, Artemis!55D1D28B91D9, Artemis!08C259690876, Artemis!AA0B88322D9D
77.78%

McAfee Web Gateway
Artemis!553CD710BF51, Artemis!A34F9AC02DB1, Artemis!55D1D28B91D9, Artemis!08C259690876, Artemis!AA0B88322D9D
77.78%

herdProtect (fuzzy)
a variant of f3daed5ebc041cc2e2f4153e44895e17d218e7ab, a variant of 3fbc6de9f1334f53143aea533acb7da976cc53a2, a variant of e7324fdf72fa6976b8d17215cef5ceeb292a3cb5
66.67%

The domain dl2.iq9download.com has been seen to resolve to the following 5 IP addresses.

May 3, 2015

cdn-208-111-160-6.iad.llnw.net
September 3, 2014

cdn-208-111-161-254.iad.llnw.net
September 3, 2014

February 5, 2014

February 5, 2014

File downloads found at URLs served by dl2.iq9download.com.

30 / 68    (Adware)

16 / 68    (Adware)

23 / 68    (Adware)
http://dl2.iq9download.com/lm/.../7zip_bimo.exe  (0b707c30b2dc59c2ac3751e46c77ec00)

27 / 68    (Adware)
http://dl2.iq9download.com/lm/.../coretemp_1236.exe  (d8570961730fb9c2ab3645401aae3a1d)

23 / 68    (Adware)

30 / 68    (Adware)

15 / 68    (Adware)

15 / 68    (Adware)

13 / 68    (Adware)
http://dl2.iq9download.com/lm/.../coretemp_1236.exe  (coretemp_1236(vérifier températur du processeur).exe)

29 / 68    (Adware)

5 / 68      (false positives)

The following 29 files have been seen to comunicate with dl2.iq9download.com in live environments.

 
Latest 20 of 44 files

URL:
http://dl2.iq9download.com/

Google Analytics:
UA-2249740

Title:
“Iq9download.com”

Description:
“Find Cash Advance, Debt Consolidation and more at Iq9download.com. Get the best of Insurance or Free Credit Report, browse our section on Cell Phones or learn about Life Insurance. Iq9download.com is the site for Cash Advance.”

Web server:
Microsoft-IIS/7.5 (ASP.NET) (Version: 4.0.30319)

30 of 305 related domains

Remove Malware from dl2.iq9download.com - Powered by Reason Core Security