www.onedownloader.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain www.onedownloader.com is registered by proxy through GODADDY.COM, LLC and was originally registered in September of 2013. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Amsterdam, Noord-Holland within Netherlands.
Remove Malware from www.onedownloader.com - Powered by Reason Core Security
Registrar:
GODADDY.COM, LLC

Server location:
Noord-Holland, Netherlands (NL)

Create date:
Thursday, September 12, 2013

Expires date:
Monday, September 12, 2016

Updated date:
Friday, August 22, 2014

ASN:
AS32475 SINGLEHOP-INC - SingleHop,US

Root domain:

Scanner detections:
Detections  (60% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Optional.BeijingAmazGameAgeInternetTechnologyCo.J, Win32.Generic.SCCE.Installer.Meta, PUP.Air Software.AirSoftware.Bundler (M), PUP.Air Software.DownloadManager.Bundler (M), PUP.Air Software.DownloadAssistant.Bundler (M), PUP.InstallCore.Installer.Installer (M)
80.00%

Dr.Web
Win32.Sector.21, Adware.NextLive.2, Adware.OpenCandy.39, Adware.OpenCandy.163, Trojan.SMSSend.5095, Adware.Downware.2035
22.86%

Avira AntiVirus
W32/Sality.AT, APPL/NextLive.opea.2, TR/Patched.Gen, Adware/AgentCV.A.15058, ADWARE/Adware.Gen
20.00%

McAfee Web Gateway
Artemis!F62C6E428738, Artemis!67A9280B7ACF, BehavesLike.Win32.Pate.bc , BehavesLike.Win32.Downloader.cc
20.00%

ESET NOD32
Win32/OpenCandy, Win32/MyPCBackup, Win32/Mobogenie, Win32/OpenCandy (variant), Win32/OpenCandy.E potentially unsafe (variant)
20.00%

Antiy Labs AVL
Trojan[:HEUR]/Win32.AGeneric, GrayWare[AdWare:not-a-virus]/Win32.AirAdInstaller, Trojan/Win32.TSGeneric
20.00%

K7 AntiVirus
Trojan , Unwanted-Program
17.14%

K7 Gateway Antivirus
Trojan , Unwanted-Program
17.14%

NANO AntiVirus
Trojan.Win32.NextLive.csjhvj, Trojan.Win32.OpenCandy.cufxmc, Riskware.Win32.AirAdInstaller.dbjmjg, Riskware.Win32.AirAdInstaller.cwbltv
17.14%

avast!
NSIS:NextLive-A [Adw], Win32:Adware-gen [Adw], PUP-gen [PUP], Win32:Installer-L [PUP]
17.14%

AVG
AdLoad.OpenCandy, Generic, Adware Skodna.Generic, Adware BundleApp_r.D
17.14%

F-Prot
W32/Sality.gen2, W32/AirInstall.D.gen, W32/AirInstall.C.gen, W32/A-d0922a62
14.29%

McAfee
Artemis!F62C6E428738, Artemis!67A9280B7ACF, Artemis!A66049F867BF, Artemis!087198B1243C, Trojan.Artemis!D5E91201901F
14.29%

Malwarebytes
PUP.Optional.NextLive.A, PUP.Optional.AirAdInstaller, PUP.Optional.AirInstaller
14.29%

Kaspersky
not-a-virus:HEUR:RiskTool.AndroidOS.Mobogen, not-a-virus:AdWare.Win32.AirAdInstaller
14.29%

The domain www.onedownloader.com has been seen to resolve to the following 4 IP addresses.

ps503785.dreamhost.com
January 27, 2016

server.onedownloader.com
November 25, 2015

May 6, 2015

ekiaiomcsg.c06.mtsvc.net
April 4, 2014

File downloads found at URLs served by www.onedownloader.com.

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

38 / 68    (Adware)
http://www.onedownloader.com/.../avast.exe  (avast! free antivirus 2014 setup.exe)

1 / 68

3 / 68
http://www.onedownloader.com/.../utorrent.exe  (c355d12fa264b22ba44fc67323ebe819)

0 / 68
http://www.onedownloader.com/.../realplayer.exe  (7d4da2e9dc6007edcc5196f1983418fa)

0 / 68

0 / 68
http://www.onedownloader.com/.../superantispyware.exe  (e5d349452e2265d84f8d864a8f35188c)

1 / 68      (Adware)

1 / 68      (Adware)

5 / 68      (false positives)

9 / 68      (PUP)

0 / 68
http://www.onedownloader.com/.../cyberlinkyoucam.exe  (cyberlink_youcam_downloader.exe)

6 / 68      (PUP)

19 / 68    (PUP)
http://www.onedownloader.com/.../mobogenie.exe  (67a9280b7acf4c69910b2f9b76f5cae6)

1 / 68      (Adware)
http://www.onedownloader.com/.../mp3rocket.exe  (be851610c8910f23b3dbdc9eddb42278)

1 / 68

1 / 68      (Adware)
http://www.onedownloader.com/.../windowslivemoviemaker.exe  (windows live movie maker setup.exe)

1 / 68      (Adware)

1 / 68      (Adware)

 
Latest 30 of 118 download URLs

URL:
http://www.onedownloader.com/

Title:
“Download Free Software from TrustyDownloads.com”

Description:
“#”

Web server:
Apache

Remove Malware from www.onedownloader.com - Powered by Reason Core Security