www.fixiterror.com

See PrivacyGuardian.org  (Proxy Registrant)

Domain Information

The domain www.fixiterror.com is registered by proxy through NAMESILO, LLC and was originally registered in July of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Phoenix, Arizona within the United States which resides on the CloudFlare, Inc. network. The domain uses the CloudFlare CDN, a distributed domain name server service which utilizes a number of reverse proxy IP Addresses (see below).
Registrar:
NAMESILO, LLC

Server location:
Arizona, United States (US)

Create date:
Monday, July 14, 2014

Expires date:
Thursday, July 14, 2016

Updated date:
Thursday, July 16, 2015

ASN:
AS13335 CLOUDFLARENET - CloudFlare, Inc., US

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Dr.Web
riskware program Program.Unwanted.493, riskware program Program.Unwanted.1470
100.00%

Reason Heuristics
PUP.Reimage (L), Win32.Generic.Reimage.Installer.Meta, PUP.Reimage.Installer.Meta (L)
100.00%

Bkav FE
W32.HfsAdware
66.67%

McAfee
Artemis!72CB31555DA5, Artemis!D7830F8B35ED
66.67%

Malwarebytes
PUP.Optional.ReImageRepair.A
66.67%

Fortinet FortiGate
Riskware/ReImageRepair
66.67%

Baidu Antivirus
PUA.Win32.ReImageRepair
66.67%

Trend Micro House Call
Suspicious_GEN.F47V0520
66.67%

ESET NOD32
Detection.Undefined
33.33%

Kaspersky
not-a-virus:AdWare.Win32.Pibee
33.33%

ESET NOD32
Win32/ReImageRepair.F potentially unwanted
33.33%

Clam AntiVirus
Win.Trojan.Slugin-260
33.33%

The domain www.fixiterror.com has been seen to resolve to the following 2 IP addresses.

April 16, 2016

April 16, 2016

File downloads found at URLs served by www.fixiterror.com.

2 / 68      (PUP)
http://www.fixiterror.com/download  (reimagerepair.exe)

10 / 68    (PUP)
http://www.fixiterror.com/download  (reimagerepair.exe)

10 / 68    (PUP)
http://www.fixiterror.com/download  (reimagerepair.exe)

URL:
http://www.fixiterror.com/

Title:
“Introduce How to Effectively Repair Windows Errors !”

SSL certificate subject:
CN=sni59000.cloudflaressl.com, OU=PositiveSSL Multi-Domain, OU=Domain Control Validated

SSL certificate issuer:
CN=COMODO ECC Domain Validation Secure Server CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Web server:
cloudflare-nginx (PHP/5.4.24)