www.freeaudiovideosoft.com

Tsingsoft Imagination Information Technology Co., Ltd  (via a Proxy Registrant)

Domain Information

The domain www.freeaudiovideosoft.com is registered by proxy through ENOM, INC. and was originally registered in March of 2009. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Houston, Texas within the United States which resides on the ThePlanet.com Internet Services, Inc. network. The domain is associated with the publisher Tsingsoft Imagination Information Technology Co., Ltd who is located in 北京, China.
Remove Malware from www.freeaudiovideosoft.com - Powered by Reason Core Security
Registrar:
ENOM, INC.

Server location:
Texas, United States (US)

Create date:
Friday, March 13, 2009

Expires date:
Sunday, March 13, 2016

Updated date:
Wednesday, February 11, 2015

ASN:
AS21844 THEPLANET-AS - ThePlanet.com Internet Services, Inc.

Scanner detections:
Detections  (79% detected)

Scan engine
Details
Detections

ESET NOD32
Win32/OpenCandy, Win32/Toolbar.Conduit, Win32/Toolbar.Conduit.AB (variant), Win32/OpenCandy (variant), Win32/InstallCore.PY (variant)
100.00%

Reason Heuristics
PUP.Optional.Installer.R, PUP.Conduit.Y, PUP.Conduit.V, PUP.Installer.ClientConnect.Y, PUP.Installer.ClientConnect.I, PUP.Installer.ClientConnect.S
82.61%

Malwarebytes
PUP.Optional.OpenCandy, PUP.Optional.Conduit.A, PUP.Optional.Amonetize
60.87%

VIPRE Antivirus
Conduit, Trojan.Win32.Generic, InstallCore
60.87%

Trend Micro House Call
TROJ_GEN.F47V1228, TROJ_GE.D505A53B, TROJ_GEN.F47V0414, TROJ_GEN.F47V0409, TROJ_GEN.F47V0507, Suspicious_GEN.F47V0117
34.78%

Dr.Web
Adware.Conduit.6, Adware.Conduit.96, Trojan.InstallCore.11
34.78%

AVG
MalSign.Generic
26.09%

McAfee
Artemis!AAA8D0210C07, Artemis!120FA74267A6, Artemis!59DA36247DF8, Artemis!8EEF62359254
17.39%

McAfee Web Gateway
Artemis!AAA8D0210C07, Artemis!120FA74267A6
17.39%

G Data
Win32.Application.ConduitBrothersoftTB
17.39%

K7 AntiVirus
Trojan , Unwanted-Program
17.39%

Avira AntiVirus
ADWARE/InstallCore.Gen9, ADWARE/InstallCore.Gen7
17.39%

K7 Gateway Antivirus
Trojan , Unwanted-Program
13.04%

Norman
InstallCore.CERT
13.04%

Rising Antivirus
PE:PUF.OpenCandy!1.9DE5
8.70%

The domain www.freeaudiovideosoft.com has been seen to resolve to the following 2 IP addresses.

184.173.227.117-static.reverse.softlayer.com
May 3, 2015

6a.81.7bae.static.theplanet.com
January 4, 2014

File downloads found at URLs served by www.freeaudiovideosoft.com.

1 / 68      (inconclusive)
http://www.freeaudiovideosoft.com/.../FreeAudioEditor.exe  (86d7e471bc97520c25e87fde69e3dcfb)

13 / 68    (Adware)
http://www.freeaudiovideosoft.com/.../FreeAVIMPEGWMVMP4FLVVideoJoiner.exe  (free_avi_mpeg_wmv_mp4_flv_video_joiner_tsa143k1p.exe)

15 / 68    (PUP)

2 / 68      (PUP)

10 / 68    (PUP)

9 / 68      (PUP)

2 / 68      (PUP)

4 / 68      (PUP)

4 / 68      (PUP)

2 / 68      (PUP)

6 / 68      (PUP)

1 / 68      (inconclusive)

2 / 68      (inconclusive)

1 / 68      (inconclusive)

14 / 68    (PUP)

6 / 68      (Adware)
http://www.freeaudiovideosoft.com/.../FreeAudioEditor.exe  (950a3e4b4602733876708a919c19d059)

7 / 68      (PUP)

6 / 68      (Adware)

6 / 68      (Adware)

7 / 68      (Adware)

2 / 68      (PUP)

6 / 68      (PUP)

11 / 68    (PUP)

The following file have been seen to comunicate with www.freeaudiovideosoft.com in live environments.

URL:
http://www.freeaudiovideosoft.com/

Google Analytics:
UA-23867365

Title:
“Free Audio Video Programs by FAV Software”

Description:
“FreeAudioVideo Software, audio and video software specialists - various multimedia tools and applications are provided FOR FREE (sound recorder, audio editor, YouTube downloader, YouTube converter, CD/DVD burner and ripper, ISO maker and burner, ...”

Web server:
Apache/2.4.7

Facebook:
Likes:  10
Shares:  307

Statistics are for the previous month.

Remove Malware from www.freeaudiovideosoft.com - Powered by Reason Core Security