www.downloadwizard.com

Download Manager  (via a Proxy Registrant)

Domain Information

The domain www.downloadwizard.com is registered by proxy through ENOM, INC. and was originally registered in April of 2000. This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in Houston, Texas within the United States which resides on the ThePlanet.com Internet Services, Inc. network. The domain is associated with the publisher Download Manager who is located in Vancouver, British Columbia in Canada.
Remove Malware from www.downloadwizard.com - Powered by Reason Core Security
Registrar:
ENOM, INC.

Server location:
Texas, United States (US)

Create date:
Wednesday, April 12, 2000

Expires date:
Tuesday, April 12, 2016

Updated date:
Friday, March 13, 2015

ASN:
AS21844 THEPLANET-AS - ThePlanet.com Internet Services, Inc.

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.DownloadManager.U, PUP.Installer.DownloadManager.L, PUP.Installer.DownloadManager.T, PUP.Installer.DownloadManager.N, Threat.Win.Reputation.IMP, DownloadManager.AirSoftware.a, PUP.Installer.DownloadManager.a, PUP.Installer.InstallManager.T, PUP.Installer.DownloadManager.O, PUP.Installer.DownloadAssistant.H, PUP.Installer.DownloadAssistant.L, PUP.DownloadAssistant.H, PUP.Air Software.Bundler, PUP.Adknowledge.InstallManager.Installer (M), PUP.Air Software.DownloadManager.Bundler (M), PUP.Air Software.DownloadAssistant.Bundler (M), PUP.Vittalia.InstallHelper (M)
100.00%

Malwarebytes
PUP.Optional.AirAdInstaller, PUP.Optional.AirInstaller, PUP.Optional.DownloadAssistant, PUP.Optional.BundleInstaller.A
79.41%

VIPRE Antivirus
Iminent, Threat.4150696, AirAdInstaller, Trojan.Win32.Generic, Threat.4784938, Threat.5061940, Threat.4782985
79.41%

AVG
BundleApp, InstallCore, Adware BundleApp, BundleApp_r.D, Adware Generic_r, Adware InstallCore, Adware BundleApp_r.D, Adware BundleApp.DN
79.41%

K7 Gateway Antivirus
Unwanted-Program , Trojan
79.41%

Dr.Web
Trojan.SMSSend.4979, Trojan.SMSSend.4790, Adware.Downware.2035, Trojan.Damaged.1, Trojan.SMSSend.5348, Trojan.SMSSend.4723
76.47%

K7 AntiVirus
Adware , Unwanted-Program , Trojan
76.47%

NANO AntiVirus
Riskware.Win32.AirAdInstaller.cwbkkg, Riskware.Win32.AirAdInstaller.cwblbp, Riskware.Win32.AirAdInstaller.cwanhi, Riskware.Win32.AirAdInstaller.cwgpbr
73.53%

avast!
Win32:PUP-gen [PUP], Win32:Malware-gen, Adware-gen [Adw], Win32:Adware-gen [Adw], Win32:Adware-CKC [PUP], Win32:Adware-CKD [PUP]
70.59%

Rising Antivirus
PE:PUF.Airinstall!1.9C4C, PE:Malware.XPACK-HIE/Heur!1.9C48, PE:Malware.Graftor!6.1D1F
70.59%

Panda Antivirus
Trj/Genetic.gen, Trj/OCJ.F, Adware/AirInstaller, Generic Suspicious
70.59%

Avira AntiVirus
ADWARE/Adware.Gen, TR/Trash.Gen, Adware/AgentCV.A.3144, Adware/AgentCV.A.6255, TR/Crypt.XPACK.Gen, PUA/DownloadAssistant.Gen
67.65%

Sophos
AirInstaller, PUA 'AirInstaller'
64.71%

Agnitum Outpost
PUA.AirAdInstaller, Riskware.Agent
61.76%

IKARUS anti.virus
AdWare.Airinstall, Win32.Malware, Win32.AdWare, Trojan-Spy.Zbot, AdWare.AirAdInstaller, PUA.AirAdInstaller, not-a-virus:AdWare.AirAdInstaller
61.76%

The domain www.downloadwizard.com has been seen to resolve to the following IP address.

server.rawhumor.com
February 27, 2014

File downloads found at URLs served by www.downloadwizard.com.

22 / 68    (Adware)

39 / 68    (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

42 / 68    (Adware)

37 / 68    (Adware)

31 / 68    (Adware)

41 / 68    (Adware)

26 / 68    (Adware)

16 / 68    (Adware)

25 / 68    (Adware)

22 / 68    (Adware)

37 / 68    (Adware)

39 / 68    (Adware)

30 / 68    (PUP)

1 / 68      (Adware)

URL:
http://www.downloadwizard.com/

Google Analytics:
UA-19134607

Title:
“Download Free Software”

Description:
“Download free software from our regularily updated archives.”

Web server:
Apache (PHP/5.2.9,PleskLin)

Facebook:
Likes:  3
Shares:  5
Comments:  2

Statistics are for the previous month.

Remove Malware from www.downloadwizard.com - Powered by Reason Core Security