www.easydriverpro.com

Probit Software LTD

Domain Information

The domain www.easydriverpro.com registered by Probit Software LTD was initially registered in October of 2009 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Ashburn, Virginia within the United States which resides on the Amazon.com, Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform.
Remove Malware from www.easydriverpro.com - Powered by Reason Core Security
Registrar:
GODADDY.COM, LLC

Server location:
Virginia, United States (US)

Create date:
Wednesday, October 21, 2009

Expires date:
Sunday, October 21, 2018

Updated date:
Thursday, October 22, 2015

ASN:
AS14618 AMAZON-AES - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Detections  (94% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Optional.ProbitSoftware.N, Win32.Generic.Installer.Meta, Win32.Generic.ProbitSoftware.Installer.Meta
94.44%

McAfee Web Gateway
Heuristic.BehavesLike.Win32.Suspicious-PKR.G, Artemis!B8F587D0AC33, Artemis!3A48EC5FEC50, Artemis!803CEDF9B315, Artemis!28210FDDE5FA, BehavesLike.Win32.Dropper.nh
72.22%

AVG
MalSign.Generic
72.22%

Dr.Web
Program.Unwanted.44, Trojan.DownLoader12.20934, Trojan.DownLoader11.25016, Program.Unwanted.753
61.11%

avast!
Win32:Malware-gen, Win32:Adware-gen [Adw]
55.56%

McAfee
Artemis!DAAD3B909D55, Artemis!9D08F6A629E6, Artemis!B8F587D0AC33, Artemis!3A48EC5FEC50, Artemis!803CEDF9B315, Artemis!28210FDDE5FA, Artemis!B8DC5CB87441, Artemis!9F7890067153
50.00%

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
50.00%

Trend Micro House Call
TROJ_GEN.F47V0226, TROJ_GEN.F47V0420, Suspicious_GEN.F47V0618, Suspicious_GEN.F47V0617, TROJ_GEN.F47V0509, Suspicious_GEN.F47V0819
44.44%

G Data
Win32.Trojan.Agent.03RLY4, Win32.Trojan.Agent.P0NYF2, Win32.Trojan.Agent.NVKX2X, Win32.Trojan.Agent.4MI36Z, Win32.Trojan.Agent.XALH6K
27.78%

Bkav FE
W32.HfsAdware
27.78%

SUPERAntiSpyware
Trojan
16.67%

Kaspersky
HEUR:Trojan-Downloader.Win32.Generic
11.11%

Malwarebytes
Trojan.Backdoor.MRX
5.56%

Avira AntiVirus
TR/Dldr.Agent.86944.4
5.56%

Rising Antivirus
PE:Trojan.Win32.Generic.16E11631!383850033
5.56%

The domain www.easydriverpro.com has been seen to resolve to the following 11 IP addresses.

ec2-54-225-182-178.compute-1.amazonaws.com
February 3, 2016

ec2-50-19-225-28.compute-1.amazonaws.com
January 31, 2016

ec2-107-22-242-100.compute-1.amazonaws.com
October 13, 2015

ec2-54-221-239-239.compute-1.amazonaws.com
July 16, 2015

ec2-75-101-157-37.compute-1.amazonaws.com
May 21, 2015

ec2-23-21-42-142.compute-1.amazonaws.com
May 3, 2015

ec2-184-73-157-23.compute-1.amazonaws.com
October 20, 2014

ec2-107-22-249-123.compute-1.amazonaws.com
September 4, 2014

ec2-54-243-123-210.compute-1.amazonaws.com
August 7, 2014

ec2-23-21-224-117.compute-1.amazonaws.com
April 26, 2014

ec2-23-23-118-237.compute-1.amazonaws.com
March 30, 2014

File downloads found at URLs served by www.easydriverpro.com.

6 / 68      (PUP)

6 / 68      (PUP)

6 / 68      (PUP)

6 / 68      (PUP)

10 / 68    (PUP)

3 / 68      (PUP)

3 / 68      (PUP)

6 / 68      (PUP)

10 / 68    (PUP)

9 / 68      (PUP)

6 / 68      (PUP)

6 / 68      (PUP)

The following 3 files have been seen to comunicate with www.easydriverpro.com in live environments.

URL:
http://www.easydriverpro.com/

Title:
“Easy Driver Pro”

Description:
“Easy Driver Pro is the easy way to keep your PC Drivers up to date. Get access to over 15,000,000 device drivers. Download & Install Easy Driver Pro today.”

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
Apache/2.2.29 (Amazon) (PHP/5.3.29)

Facebook:
Likes:  1
Shares:  21

Statistics are for the previous month.

Remove Malware from www.easydriverpro.com - Powered by Reason Core Security