Friday, December 7, 2007

codechard.com





Another Fake Codec Site from ESTDOMAINS,

Do NOT download any program from this website.

Note that this program is a DNS Changer.

It pretends to be a browser add-on for viewing porn which is actually a Trojan Horse program. It has the capability to install a Rootkit on to your computer to re-route your Internet searches through the bad servers to make money for them.


codechard.com


Virus Total Results: 15/32 (46.88%)

AntiVir ------> HEUR/Malware
AVG ------>Downloader.Zlob.KF
BitDefender ------>Trojan.Zlob.BYQ
CAT-QuickHeal ------>Win32.Trojan.DNSChanger.abj
Ewido ------>Downloader.Zlob.eie
Fortinet ------>W32/Zlobar.ADZ!tr
F-Secure ------>Trojan.Win32.DNSChanger.adz
Kaspersky ------>Trojan.Win32.DNSChanger.adz
Microsoft ------>Trojan:Win32/Alureon.gen!E
Panda ------>Adware/JustPorn
Prevx1 ------>Generic.Dropper.xCodec
Sophos ------>Troj/Zlobar-Fam
Symantec ------>Trojan.Zlob
TheHacker ------>Trojan/Downloader.Zlob.eie
Webwasher-Gateway ------>Heuristic.Malware

File size: 231549 bytes
MD5: d0071820c328a1985d63e86f61d5b606
SHA1: 0d92ab6bc8f25d55d9799a5c479edc751ece17b1
PEiD: -
Prevx info: http://fileinfo.prevx.com/fileinfo.asp?PX5=675A623B7D5697AB88DB03AB863BA800D8053CA9


More information:
Domain Name: codechard.com
Status: ok
Registrar: ESTDOMAINS, INC.
Referral URL: http://www.estdomains.com

Expiration Date: 2008-09-21
Creation Date: 2007-09-21
Last Update Date: 2007-12-05

Name Servers:
ns1.codechard.com
ns2.codechard.com

IP Address: 64.28.184.186
Website Status: active
Server Type: Apache/2.0.59 (FreeBSD) PHP/5.2.1 with Suhosin-Patch
Cache Date: 2007-12-07 03:09:19 MST

No comments: