Tuesday, December 4, 2007

CodecMega.net


CodecMega.net


Another Fake Codec Site from ESTDOMAINS,

Do NOT download any program from this website.

Note that this program is a DNSChanger. It pretends to be a browser add-on for viewing porn which is actually a Trojan Horse program.It has the capability to install a Rootkit on to your computer to re-route your Internet searches through the bad servers to make money for them.


CodecMega.net


Virus Total Results: 16/32 (50%)
-------------------------------------------------------
AntiVir----->HEUR/Malware
AVG----->Downloader.Zlob.KF
BitDefender----->Trojan.Zlob.BYQ
CAT-QuickHeal----->Win32.Trojan.DNSChanger.abj
eSafe----->Win32.DNSChanger.abj
Ewido----->Downloader.Zlob.eie
Fortinet----->W32/Zlobar.ABJ!tr
F-Secure----->Trojan.Win32.DNSChanger.adz
Kaspersky----->Trojan.Win32.DNSChanger.adz
Microsoft----->Trojan:Win32/Alureon.gen!E
Panda----->Adware/KeyToPorn
Prevx1----->Generic.Dropper.xCodec
Sophos----->Troj/Zlobar-Fam
Symantec----->Trojan.Zlob
TheHacker----->Trojan/Downloader.Zlob.eie

Detection rate seems to be better.

More Information:
-----------------
Domain Name: codecmega.net
Status: ok
Registrar: ESTDOMAINS, INC.
Referral URL: http://www.estdomains.com

Expiration Date: 2008-09-21
Creation Date: 2007-09-21
Last Update Date: 2007-12-02

Name Servers:
ns1.codecmega.net
ns2.codecmega.net

IP Address: 64.28.184.185
Website Status: active
Server Type: Apache/2.0.59 (FreeBSD) PHP/5.2.1 with Suhosin-Patch
Cache Date: 2007-12-04 06:15:38 MST