www.ocrtoword.com

WHOISGUARD, INC.  (Proxy Registrant)

Domain Information

The domain www.ocrtoword.com is registered by proxy through ENOM, INC. and was originally registered in April of 2012. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Houston, Texas within the United States which resides on the ThePlanet.com Internet Services, Inc. network.
Remove Malware from www.ocrtoword.com - Powered by Reason Core Security
Registrar:
ENOM, INC.

Server location:
Texas, United States (US)

Create date:
Wednesday, April 11, 2012

Expires date:
Monday, April 11, 2016

Updated date:
Thursday, March 12, 2015

ASN:
AS21844 THEPLANET-AS - ThePlanet.com Internet Services, Inc.

Root domain:

Scanner detections:
Detections  (93% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Optional.Installer.N, PUP.Bundler.TsingsoftImaginationInformationTechnologyCo.Installer.Meta (L), PUP.Optional.TechEvolveGMBH.N
93.33%

ESET NOD32
Win32/InstallMonetizer.AF, Win32/Adware.RK.AP, Win32/OpenCandy (variant), Win32/InstallCore.PY (variant), Win32/InstallCore.RB (variant)
66.67%

VIPRE Antivirus
InstallCore, Threat.4786018
60.00%

Norman
InstallCore.CERT
60.00%

K7 Gateway Antivirus
Trojan , Unwanted-Program
46.67%

K7 AntiVirus
Trojan , Unwanted-Program
46.67%

Dr.Web
Trojan.InstallCore.11
46.67%

Avira AntiVirus
ADWARE/InstallCore.Gen9, Adware/InstallCore.692760, ADWARE/InstallCore.Gen7
40.00%

Baidu Antivirus
Adware.Win32.InstallCore
40.00%

McAfee
Artemis!2306BD47C1B3, Artemis!D027CD87018F, Artemis!57425AD9A933, Artemis!7C2C9AB90A46, Artemis!6E07B12682FC
33.33%

McAfee Web Gateway
Artemis
33.33%

Fortinet FortiGate
Riskware/InstallCore
26.67%

Sophos
Generic PUA HN, Generic PUA EO, Generic PUA MF, Generic PUA AK
26.67%

Trend Micro House Call
Suspicious_GEN.F47V1117, Suspicious_GEN.F47V0107, Suspicious_GEN.F47V0119, Suspicious_GEN.F47V0214
26.67%

Malwarebytes
PUP.Optional.Amonetize
20.00%

The domain www.ocrtoword.com has been seen to resolve to the following 2 IP addresses.

184.173.227.114-static.reverse.softlayer.com
May 3, 2015

67.81.7bae.static.theplanet.com
April 16, 2014

File downloads found at URLs served by www.ocrtoword.com.

14 / 68    (PUP)
http://www.ocrtoword.com/FreeOCRtoWord.exe  (57425ad9a9335b1a4034a7c5f11f6c6d)

15 / 68    (PUP)
http://www.ocrtoword.com/FreeOCRtoWord.exe  (7c2c9ab90a46ca352fa306f977d8f61e)

7 / 68      (PUP)

7 / 68      (PUP)
http://www.ocrtoword.com/FreeOCRtoWord.exe  (4621e79c7ad427bbcd7250389e327181)

9 / 68      (PUP)

5 / 68      (PUP)

5 / 68      (PUP)
http://www.ocrtoword.com/FreeOCRtoWord.exe  (69c655cff588327a493cf00f90b0ecdd)

15 / 68    (PUP)

9 / 68      (PUP)
http://www.ocrtoword.com/FreeOCRtoWord.exe  (6e07b12682fc6d378648983d98516b24)

9 / 68      (PUP)
http://www.ocrtoword.com/FreeOCRtoWord.exe  (efddc6474cb893a7e0991a1925dda169)

1 / 68      (PUP)
http://www.ocrtoword.com/FreeOCRtoWord.exe  (4725bdc1b934883dd0dd2bc43ff78e80)

15 / 68    (PUP)
http://www.ocrtoword.com/FreeOCRtoWord.exe  (d027cd87018f61a35fa726c36228207b)

15 / 68    (PUP)
http://www.ocrtoword.com/FreeOCRtoWord.exe  (2306bd47c1b3968beac185d2f0f37762)

14 / 68    (PUP)

1 / 68      (PUP)
http://www.ocrtoword.com/FreeOCRtoWord.exe  (2d8b1817bf3720936d67ea221d66b827)

1 / 68      (PUP)
http://www.ocrtoword.com/FreeOCRtoWord.exe  (48745377711cc843258852375503ae72)

2 / 68      (PUP)
http://www.ocrtoword.com/FreeOCRtoWord.exe  (0624dcb3ed6d1e5c3ac8473d03da9dbb)

1 / 68      (inconclusive)
http://www.ocrtoword.com/FreeOCRtoWord.exe  (4d5f297999d88693f1ba8a519bd52731)

2 / 68      (PUP)
http://www.ocrtoword.com/FreeOCRtoWord.exe  (95cab08931ad6aed102c5a718bed7faa)

URL:
http://www.ocrtoword.com/

Google Analytics:
UA-30955106

Title:
“TechCandy Software - Free OCR to Word - Easy Free OCR Image to Word Converter”

Description:
“Our free OCR to Word converter enables you to convert images to Word with high accuracy.”

Web server:
Apache/2.4.7 (PHP/5.5.9-1ubuntu4.14)

Facebook:
Likes:  8
Shares:  313
Comments:  13

Statistics are for the previous month.

Remove Malware from www.ocrtoword.com - Powered by Reason Core Security