www.freeaudiovideosoft.com

Tsingsoft Imagination Information Technology Co., Ltd  (via a Proxy Registrant)

Domain Information

The domain www.freeaudiovideosoft.com is registered by proxy through ENOM, INC. and was originally registered in March of 2009. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Houston, Texas within the United States which resides on the ThePlanet.com Internet Services, Inc. network. The domain is associated with the publisher Tsingsoft Imagination Information Technology Co., Ltd who is located in 北京, China.
Registrar:
ENOM, INC.

Server location:
Texas, United States (US)

Create date:
Friday, March 13, 2009

Expires date:
Monday, March 13, 2017

Updated date:
Friday, February 12, 2016

ASN:
AS21844 THEPLANET-AS - ThePlanet.com Internet Services, Inc.

Scanner detections:
Detections  (95% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Optional.Installer.R, PUP.Conduit.Y, PUP.Conduit.V, PUP.Installer.ClientConnect.Y, PUP.Installer.ClientConnect.I, PUP.Installer.ClientConnect.S, Win32.Generic, PUP.Bundler.Tsingsof.Installer.Meta (L), PUP.InstallCore.Huaxinwa.Installer.Meta (M)
100.00%

ESET NOD32
Win32/OpenCandy, Win32/Toolbar.Conduit, Win32/Toolbar.Conduit.AB (variant), Win32/OpenCandy (variant), Win32/InstallCore.PY (variant), Win32/Toolbar.Conduit potentially unwanted
77.78%

Malwarebytes
PUP.Optional.OpenCandy, PUP.Optional.Conduit.A, PUP.Optional.Amonetize
38.89%

VIPRE Antivirus
Conduit, Trojan.Win32.Generic, InstallCore
38.89%

Trend Micro House Call
TROJ_GEN.F47V1228, TROJ_GE.D505A53B, TROJ_GEN.F47V0414, TROJ_GEN.F47V0409, TROJ_GEN.F47V0507, Suspicious_GEN.F47V0117
22.22%

Dr.Web
Adware.Conduit.6, Adware.Conduit.96, Trojan.InstallCore.11
22.22%

AVG
MalSign.Generic
16.67%

McAfee
Artemis!AAA8D0210C07, Artemis!120FA74267A6, Artemis!59DA36247DF8, Artemis!8EEF62359254
11.11%

G Data
Win32.Application.ConduitBrothersoftTB
11.11%

K7 AntiVirus
Trojan , Unwanted-Program
11.11%

Avira AntiVirus
ADWARE/InstallCore.Gen9, ADWARE/InstallCore.Gen7
11.11%

Norman
InstallCore.CERT
8.33%

Rising Antivirus
PE:PUF.OpenCandy!1.9DE5
5.56%

Emsisoft Anti-Malware
Gen:Heur.Conjar
5.56%

Baidu Antivirus
Adware.Win32.Conduit, Adware.Win32.InstallCore
5.56%

The domain www.freeaudiovideosoft.com has been seen to resolve to the following 2 IP addresses.

184.173.227.117-static.reverse.softlayer.com
May 3, 2015

6a.81.7bae.static.theplanet.com
January 4, 2014

File downloads found at URLs served by www.freeaudiovideosoft.com.

1 / 68      (PUP)

1 / 68      (PUP)
http://www.freeaudiovideosoft.com/.../FreeAudioEditor.exe  (27fccbeb22f719d5e11e4a48c06d9dde)

1 / 68      (PUP)
http://www.freeaudiovideosoft.com/.../FreeMP3Joiner.exe  (96034c4f335df2d5b7c5d2e07f5da2db)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

0 / 68
http://www.freeaudiovideosoft.com/.../index.php  (2f1a33292ac3e652385bad85a0f53284)

1 / 68      (PUP)

1 / 68      (PUP)

2 / 68      (PUP)

2 / 68      (PUP)

14 / 68    (PUP)

8 / 68      (PUP)

8 / 68      (PUP)

3 / 68      (PUP)

2 / 68      (PUP)

6 / 68      (PUP)

2 / 68      (PUP)

2 / 68      (PUP)

6 / 68      (Adware)

7 / 68      (Adware)

The following 27 files have been seen to comunicate with www.freeaudiovideosoft.com in live environments.

 
Latest 20 of 27 files

URL:
http://www.freeaudiovideosoft.com/

Google Analytics:
UA-23867365

Title:
“Free Audio Video Programs by FAV Software”

Description:
“FreeAudioVideo Software, audio and video software specialists - various multimedia tools and applications are provided FOR FREE (sound recorder, audio editor, YouTube downloader, YouTube converter, CD/DVD burner and ripper, ISO maker and burner, ...”

Web server:
Apache/2.4.7

Facebook:
Likes:  10
Shares:  307

Statistics are for the previous month.