uninstaller.co

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain uninstaller.co is registered by proxy through GODADDY.COM, INC. and was originally registered in October of 2013. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Arlington Heights, Illinois within the United States which resides on the GigeNET network.
Remove Malware from uninstaller.co - Powered by Reason Core Security
Registrar:
GODADDY.COM, INC.

Server location:
Illinois, United States (US)

Create date:
Wednesday, October 30, 2013

Expires date:
Saturday, October 29, 2016

Updated date:
Thursday, October 29, 2015

ASN:
AS32181 ASN-GIGENET - GigeNET

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.ParetoLogic.Optional.Installer.Meta (L)
100.00%

Trend Micro House Call
Suspicious_GEN.F47V1206
12.50%

Dr.Web
riskware program Program.Unwanted.686
12.50%

F-Secure
Gen:Adware.BrowseFox.1
12.50%

The domain uninstaller.co has been seen to resolve to the following 2 IP addresses.

shaynesherman.com
May 5, 2015

shaynesherman.com
February 5, 2014

File downloads found at URLs served by uninstaller.co.

1 / 68      (PUP)
http://uninstaller.co/b/recommends/.../m.php  (regcureprosetup_52559eaf-95c8-44eb-99f6-c27a0c09c080_.exe)

3 / 68      (PUP)
http://uninstaller.co/b/recommends/.../m.php  (regcureprosetup_edcdfb75-9201-4924-b750-0fd0009942d1_.exe)

1 / 68      (PUP)

2 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

The following 3 files have been seen to comunicate with uninstaller.co in live environments.

URL:
http://uninstaller.co/

Google Analytics:
UA-9081991

Title:
“Windows© Support: How to Uninstall Programs”

Description:
“Scan, detect and automatically fix all issues related to on your PC. how to guide.”

Web server:
Apache/2.4.12 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4 (PHP/5.5.25)

Remove Malware from uninstaller.co - Powered by Reason Core Security