i.facemoods.com

VoloNet Ltd.

Domain Information

The domain i.facemoods.com registered by VoloNet Ltd. was initially registered in July of 2009 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Providence, Utah within the United States which resides on the Hosting Services, Inc. network.
Remove Malware from i.facemoods.com - Powered by Reason Core Security
Registrar:
GODADDY.COM, LLC

Server location:
Utah, United States (US)

Create date:
Thursday, July 23, 2009

Expires date:
Saturday, July 23, 2016

Updated date:
Sunday, June 28, 2015

ASN:
AS36351 SOFTLAYER - SoftLayer Technologies Inc.,US

Root domain:

Scanner detections:
Detections  (75% detected)

Scan engine
Details
Detections

K7 Gateway Antivirus
Trojan , Unwanted-Program
85.71%

K7 AntiVirus
Trojan , Unwanted-Program
85.71%

F-Prot
W32/InstallCore.G4.gen, W32/InstallCore.I.gen
85.71%

avast!
Win32:FunMood-A [PUP], Win32:InstallCore-J [PUP]
85.71%

Avira AntiVirus
ADWARE/InstallCore.Gen
85.71%

ESET NOD32
Win32/InstallCore.BH (variant), Win32/InstallCore (variant)
85.71%

Reason Heuristics
PUP.Installer.Volonet.J
71.43%

Dr.Web
Adware.Funmoods.3, Adware.InstallCore.6
71.43%

Trend Micro House Call
TROJ_GEN.F47V0722, TROJ_SPNR.0CE413
71.43%

Baidu Antivirus
Trojan.Win32.InstallCore
71.43%

Kaspersky
not-a-virus:WebToolbar.Win32.InstallCore
71.43%

Fortinet FortiGate
Riskware/InstallCore
71.43%

CMC Antivirus
WebToolbar.Win32.InstallCore!O
71.43%

NANO AntiVirus
Riskware.Win32.InstallToolbar.crpgoq
71.43%

Trend Micro
TROJ_SPNR.0CE413
71.43%

The domain i.facemoods.com has been seen to resolve to the following 6 IP addresses.

April 11, 2014

April 11, 2014

April 11, 2014

April 11, 2014

April 11, 2014

April 11, 2014

File downloads found at URLs served by i.facemoods.com.

0 / 68
http://i.facemoods.com/gppc/.../Facemoods.exe  (697308423434a553359088dfd8832d9c)

24 / 68    (Adware)
http://i.facemoods.com/gppc/.../Facemoods.exe  (c1d42bcacf50935b42b0573dcb10b80a)

1 / 68      (inconclusive)
http://i.facemoods.com/wbst/.../Facemoods.exe  (2dc1b31be28d002c6dac405667054643)

25 / 68    (Adware)
http://i.facemoods.com/gppc/wr/.../Facemoods.exe  (13f77bd328ddc2ad52efdacfd5da1c13)

24 / 68    (Adware)
http://i.facemoods.com/gppc/.../Facemoods.exe  (9957b0472bc21740d1424781d6306277)

27 / 68    (Adware)
http://i.facemoods.com/gppc/wr/.../Facemoods.exe  (2dfc4784a9ce7a320393c15ce5fc5c49)

27 / 68    (Adware)
http://i.facemoods.com/gppc/.../Facemoods.exe  (be82e1ecd89b0829c3e73bfc3369c850)

8 / 68      (Adware)

8 / 68      (Adware)
http://i.facemoods.com/tlv/.../Facemoods.exe  (icreinstall_facemoods.exe)

8 / 68      (Adware)

8 / 68      (Adware)
http://i.facemoods.com/gppc/.../Facemoods.exe  (icreinstall_facemoods.exe)

8 / 68      (Adware)

URL:
http://i.facemoods.com/

Web server:
nginx/1.0.10

Remove Malware from i.facemoods.com - Powered by Reason Core Security