CLEAN MX realtime database
public access query for virus URL statistics
Totally watched: 20263, to down: 0, to up: 0, changed ip: 0
As of 2010-09-02 21:05:38 CEST
Subscribe to the VirusWatch Mailing list, updated hourly

This database consists of Virus URI, collected and verified since Feb 2006

If you detect URI'S concerning your netblock, already closed... you have made a good job, otherwise please close them as soon as possible.

to look at some nice charts, there are complete statisticsstatistics for this database
Attention: all URI'S are manually verified, but not cross-checked for real viruses function in this moment you make this query.(Sites may have been closed already..)
Our automatic Viruswalker process is scheduled every hour, so you may see now a incident and this one will be resolved later on.
So please keep on sending close-feedbacks to us...

if you have questions, criticism, wishes or ... do not hesitate to contact us at abuse@clean-mx.de
Our PBX is down you may reach us by cell phone +49 171 4802507 ...
Query as xml: Same query as xml output
TIMERS: Runtime Query: 0.7274 Seconds
helpLine help#descendigascending helpDatedescendigascending helpCloseddescendigascending helphours helpcontributordescendigascending helpvirusnamedescendigascending helpURLdescendigascending helpip state helpresponsedescendigascending helpIp initialdescendigascending helpAS#descendigascending helpip reviewdescendigascending helpURLdescendigascending helpDomaindescendigascending helpcountrydescendigascending helpsourcedescendigascending helpemaildescendigascending helpinetnumdescendigascending helpnetnamedescendigascending helpdescrdescendigascending helpns1descendigascending helpns2descendigascending helpns3descendigascending helpns4descendigascending helpns5descendigascending helpURLdescendigascending
1 645686Report false positive Report closed case make a suggestion 2010-09-02 21:00:56     follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
11/39 (28,21%) 
 
Trojan/Win32.Scar.gen
Win32:Malware-gen
Generic19.DEW
Gen:Trojan.Heur.ZGY.5
(Suspicious)
-
DNAScan
Gen:Trojan.Heur.ZGY.5
Gen:Trojan.Heur.ZGY.5
Trojan.Win32.Scar.crez
Artemis!6EE6AC3D8451
Artemis!6EE6AC3D8451
Trj/CI.A 
 lookup in virustotal.com (6ee6ac3d845195f3795db865f3d8985c)-->[http://www.virustotal.com/file-scan/report.html?id=45360ac5b728502eebedcb7cde01af4cb9493f55a4cab961c20b9199f6a3887e-1283454182]lookup in threatexpert.comlookup the sha256(45360ac5b728502eebedcb7cde01af4cb9493f55a4cab961c20b9199f6a3887e) in comodo.comfollow up this md5sum(6ee6ac3d845195f3795db865f3d8985c)follow up this itemfollow up this virusname (Trojan%2FWin32.Scar.gen) as RSS-Feedfollow up this malware(Trojan%2FWin32.Scar.gen) for scanner (Antiy_AVL) in md5 table11/39 (28,21%) Trojan/Win32.Scar.gen
Safe Virus-Viewer and Analyser may take a minute to complete http://polozarchitects.com/Atualizacao_D ...  up No previous evidence recordedSaved evidence (450560 Bytes) of last contact as txt September 02 2010 13:40:24 CEST. aliveSaved log of last contact as txt September 02 2010 21:02:00 CEST. SenderBaselookup 74.220.202.16 at Rus CERT university stuttgart germanylookup 74.220.202.16 at ARINfollow up this item(ip) in same window 74.220.202.16 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS11798) in networks tablefollow up this itemfollow up this AS (AS11798) as RSS-Feed AS11798 SenderBaselookup 74.220.202.16 at Rus CERT university stuttgart germanylookup 74.220.202.16 at ARINfollow up this item(review) in same window 74.220.202.16 Safe Virus-Viewer and Analyser may take a minute to complete http://polozarchitects.com/Atualizacao_D ... follow up this domain(polozarchitects.com) polozarchitects.com follow up this itemfollow up this country (US) as RSS-Feed US follow up this itemfollow up this region (ARIN) as RSS-Feed ARIN follow up this itemfollow up this enail (abuse@bluehost.com) as RSS-Feed abuse@bluehost.com follow up this itemfollow up this item 74.220.192.0 - 74.220.207.255 follow up this item BLUEHOST-NETWORK-2 follow up this item Bluehost Inc. BLUEH-2 1548 North Technology Way #D13 Orem UT 84097 follow up this item ns2.hostmonster.com follow up this item ns1.hostmonster.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://polozarchitects.com/Atualizacao_D ...
2 645675Report false positive Report closed case make a suggestion 2010-09-02 20:40:03     follow up this itemfollow up this contributor (sub12) as RSS-Feed sub12possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
0/39 (0.00%) 
 virustotal
no
evidence 
 lookup in virustotal.com (5fc9211d9be36de9f5a4453fa021770a)-->[http://www.virustotal.com/file-scan/report.html?id=90846d46bcf1244935eb92b192445f3ec51c56cb5e214cbdcbac8371c7824376-1283454208]follow up this md5sum(5fc9211d9be36de9f5a4453fa021770a)follow up this itemfollow up this virusname (unknown_html) as RSS-Feedfollow up this malware(unknown_html) for scanner (undef) in md5 table0/39 (0.00%) unknown_html
Safe Virus-Viewer and Analyser may take a minute to complete http://211.104.39.245/invite/91.exe  up No previous evidence recordedSaved evidence (27136 Bytes) of last contact as txt September 02 2010 12:39:44 CEST. aliveSaved log of last contact as txt September 02 2010 21:02:27 CEST. SenderBaselookup 211.104.39.245 at Rus CERT university stuttgart germanylookup 211.104.39.245 at apnicfollow up this item(ip) in same window 211.104.39.245 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS4766) in networks tablefollow up this itemfollow up this AS (AS4766) as RSS-Feed AS4766 SenderBaselookup 211.104.39.245 at Rus CERT university stuttgart germanylookup 211.104.39.245 at apnicfollow up this item(review) in same window 211.104.39.245 Safe Virus-Viewer and Analyser may take a minute to complete http://211.104.39.245/invite/91.exe follow up this domain(211.104.39.245) 211.104.39.245 follow up this itemfollow up this country (KR) as RSS-Feed KR follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@kornet.net) as RSS-Feed abuse@kornet.net follow up this itemfollow up this item 211.104.0.0 - 211.105.255.255 follow up this item KORNET-KR follow up this item Korea Telecom follow up this item  follow up this item  follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://211.104.39.245/invite/91.exe
3 645679Report false positive Report closed case make a suggestion 2010-09-02 20:36:27     follow up this itemfollow up this contributor (sub5) as RSS-Feed sub5possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
27/39 (69,23%) 
 
HTML/Agent
PHP/BackDoor.AR
Backdoor/PHP.Agent
PHP/Agent.AK
PHP:Agent-L
PHP/BackDoor.AN
Trojan.Script.248269
PHP.Shell-8
UnclassifiedMalware
PHP.Shellbot.10
PHP/Coverka.B
PHP/Agent.AK
Trojan.Script.248269
Trojan.Script.248269
Backdoor.PHP.Agent
Backdoor
 
 lookup in virustotal.com (81ca16c92e50478ca1112d1332352080)-->[http://www.virustotal.com/file-scan/report.html?id=9feb2b97ecf60ed845dbd57b3d79347e7c3a29a3525cf63da75b220367d022fe-1283454208]follow up this md5sum(81ca16c92e50478ca1112d1332352080)follow up this itemfollow up this virusname (PHP%2FBackDoor.AR) as RSS-Feedlookup Virusname at avirafollow up this malware(PHP%2FBackDoor.AR) for scanner (avira) in md5 table27/39 (69,23%) PHP/BackDoor.AR
Safe Virus-Viewer and Analyser may take a minute to complete http://getemgirlfriday.com/news//list/id ...  up No previous evidence recordedSaved evidence (2162 Bytes) of last contact as txt August 29 2010 01:44:13 CEST. aliveSaved log of last contact as txt September 02 2010 21:02:20 CEST. SenderBaselookup 75.126.202.88 at Rus CERT university stuttgart germanylookup 75.126.202.88 at ARINfollow up this item(ip) in same window 75.126.202.88 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS36351) in networks tablefollow up this itemfollow up this AS (AS36351) as RSS-Feed AS36351 SenderBaselookup 75.126.202.88 at Rus CERT university stuttgart germanylookup 75.126.202.88 at ARINfollow up this item(review) in same window 75.126.202.88 Safe Virus-Viewer and Analyser may take a minute to complete http://getemgirlfriday.com/news//list/id ... follow up this domain(getemgirlfriday.com) getemgirlfriday.com follow up this itemfollow up this country (US) as RSS-Feed US follow up this itemfollow up this region (ARIN) as RSS-Feed ARIN follow up this itemfollow up this enail (ipadmin@softlayer.com) as RSS-Feed ipadmin@softlayer.com follow up this itemfollow up this item 75.126.0.0 - 75.126.255.255 follow up this item SOFTLAYER-4-3 follow up this item SoftLayer Technologies Inc. SOFTL 1950 N Stemmons Freeway Dallas TX 75207 follow up this item ns101.whbdns.com follow up this item ns100.whbdns.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://getemgirlfriday.com/news//list/id ...
4 645678Report false positive Report closed case make a suggestion 2010-09-02 20:36:23     follow up this itemfollow up this contributor (sub5) as RSS-Feed sub5possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
11/39 (28,21%) 
 
TR/Script.77
PHP/Generic
Trojan.Script.468510
PHP.Id-30
Trojan.Script.468510
Trojan.Script.468510
Virus.PHP.SuspectCRC
IrcBot.BBNF
Trojan.Script.468510
Malware.PHP-Backdoor
PHP.Backdoor.Trojan 
 lookup in virustotal.com (dc7b2fd7417f4ea1917ac8b7284fecba)-->[http://www.virustotal.com/file-scan/report.html?id=608d00cd945efcc2c71ce8102b4ba806881e1f0d4ad755597c31e0700c75fd1d-1283454280]follow up this md5sum(dc7b2fd7417f4ea1917ac8b7284fecba)follow up this itemfollow up this virusname (TR%2FScript.77) as RSS-Feedlookup Virusname at avirafollow up this malware(TR%2FScript.77) for scanner (avira) in md5 table11/39 (28,21%) TR/Script.77
Safe Virus-Viewer and Analyser may take a minute to complete http://getemgirlfriday.com/news//list/id ...  up No previous evidence recordedSaved evidence (77 Bytes) of last contact as txt August 29 2010 01:43:54 CEST. aliveSaved log of last contact as txt September 02 2010 21:02:21 CEST. SenderBaselookup 75.126.202.88 at Rus CERT university stuttgart germanylookup 75.126.202.88 at ARINfollow up this item(ip) in same window 75.126.202.88 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS36351) in networks tablefollow up this itemfollow up this AS (AS36351) as RSS-Feed AS36351 SenderBaselookup 75.126.202.88 at Rus CERT university stuttgart germanylookup 75.126.202.88 at ARINfollow up this item(review) in same window 75.126.202.88 Safe Virus-Viewer and Analyser may take a minute to complete http://getemgirlfriday.com/news//list/id ... follow up this domain(getemgirlfriday.com) getemgirlfriday.com follow up this itemfollow up this country (US) as RSS-Feed US follow up this itemfollow up this region (ARIN) as RSS-Feed ARIN follow up this itemfollow up this enail (ipadmin@softlayer.com) as RSS-Feed ipadmin@softlayer.com follow up this itemfollow up this item 75.126.0.0 - 75.126.255.255 follow up this item SOFTLAYER-4-3 follow up this item SoftLayer Technologies Inc. SOFTL 1950 N Stemmons Freeway Dallas TX 75207 follow up this item ns101.whbdns.com follow up this item ns100.whbdns.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://getemgirlfriday.com/news//list/id ...
5 645677Report false positive Report closed case make a suggestion 2010-09-02 20:26:06     follow up this itemfollow up this contributor (sub5) as RSS-Feed sub5possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
20/39 (51,28%) 
 
PHP/Pbot.A.10
PHP/Pbot.A
PHP:Pbot-A
PHP/BackDoor.Q
Backdoor.PHP.Pbot.A
PHP.Shell-11
PHP.Shellbot.8
PHP/Pbot.A
Backdoor.PHP.Pbot.A
Backdoor.PHP.Pbot.A
not-a-virus:NetTool.PHP.Pbot
Trojan
Backdoor.PHP.Pbot.g
PHP/Ircbot.BBPU
Malware.PHP-Backdoor
Mal/PBot-A 
 lookup in virustotal.com (57335d85311ed6e70c4c40ae0f1a6fc8)-->[http://www.virustotal.com/file-scan/report.html?id=8356efbe6308bdaa1e82c21c83f45a100e660a29f591768eeed207fad3cca9e8-1283454185]follow up this md5sum(57335d85311ed6e70c4c40ae0f1a6fc8)follow up this itemfollow up this virusname (PHP%2FPbot.A.10) as RSS-Feedlookup Virusname at avirafollow up this malware(PHP%2FPbot.A.10) for scanner (avira) in md5 table20/39 (51,28%) PHP/Pbot.A.10
Safe Virus-Viewer and Analyser may take a minute to complete http://nani69.fileave.com/moro2.txt?  up No previous evidence recordedSaved evidence (8116 Bytes) of last contact as txt August 29 2010 13:32:41 CEST. aliveSaved log of last contact as txt September 02 2010 21:02:23 CEST. SenderBaselookup 64.62.181.43 at Rus CERT university stuttgart germanylookup 64.62.181.43 at ARINfollow up this item(ip) in same window 64.62.181.43 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS6939) in networks tablefollow up this itemfollow up this AS (AS6939) as RSS-Feed AS6939 SenderBaselookup 64.62.181.43 at Rus CERT university stuttgart germanylookup 64.62.181.43 at ARINfollow up this item(review) in same window 64.62.181.43 Safe Virus-Viewer and Analyser may take a minute to complete http://nani69.fileave.com/moro2.txt? follow up this domain(fileave.com) fileave.com follow up this itemfollow up this country (US) as RSS-Feed US follow up this itemfollow up this region (ARIN) as RSS-Feed ARIN follow up this itemfollow up this enail (abuse@he.net) as RSS-Feed abuse@he.net follow up this itemfollow up this item 64.62.128.0 - 64.62.255.255 follow up this item HURRICANE-4 follow up this item Hurricane Electric, Inc. HURC 760 Mission Court Fremont CA 94539 follow up this item ns2.ripside.com follow up this item ns1.ripside.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://nani69.fileave.com/moro2.txt?
6 645681Report false positive Report closed case make a suggestion 2010-09-02 20:16:36     follow up this itemfollow up this contributor (sub5) as RSS-Feed sub5possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
29/38 (76,32%) 
 
HTML/Xema
BDS/PHP.ali.1
Backdoor/PHP.Agent
PHP/Small.D
PHP:C99Shell-F
BackDoor.Generic_c.BTI
Backdoor.PHP.ALI
PHP.Shell-23
UnclassifiedMalware
PHP/Small.A
PHP/Small.D
Exploit:PHP/Preamble.A
Backdoor.PHP.ALI
Backdoor.PHP.Small.o
Backdoor
Backdoor.PHP.Age 
 lookup in virustotal.com (f1a9b4e4b207cd38641061e1b72d4775)-->[http://www.virustotal.com/file-scan/report.html?id=0b3eef46d7111939962db133d2e75530fbb7946d92a33195ca6b7f2e1affe43a-1283454246]follow up this md5sum(f1a9b4e4b207cd38641061e1b72d4775)follow up this itemfollow up this virusname (BDS%2FPHP.ali.1) as RSS-Feedlookup Virusname at avirafollow up this malware(BDS%2FPHP.ali.1) for scanner (avira) in md5 table29/38 (76,32%) BDS/PHP.ali.1
Safe Virus-Viewer and Analyser may take a minute to complete http://danpshy.freewebhostx.com/test.txt ...  up No previous evidence recordedSaved evidence (1165 Bytes) of last contact as txt September 02 2010 06:58:15 CEST. aliveSaved log of last contact as txt September 02 2010 21:02:16 CEST. SenderBaselookup 69.162.119.163 at Rus CERT university stuttgart germanylookup 69.162.119.163 at ARINfollow up this item(ip) in same window 69.162.119.163 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS46475) in networks tablefollow up this itemfollow up this AS (AS46475) as RSS-Feed AS46475 SenderBaselookup 69.162.119.163 at Rus CERT university stuttgart germanylookup 69.162.119.163 at ARINfollow up this item(review) in same window 69.162.119.163 Safe Virus-Viewer and Analyser may take a minute to complete http://danpshy.freewebhostx.com/test.txt ... follow up this domain(freewebhostx.com) freewebhostx.com follow up this itemfollow up this country (US) as RSS-Feed US follow up this itemfollow up this region (ARIN) as RSS-Feed ARIN follow up this itemfollow up this enail (noc@limestonenetworks.com) as RSS-Feed noc@limestonenetworks.com follow up this itemfollow up this item 69.162.64.0 - 69.162.127.255 follow up this item LSN-DLLSTX-2 follow up this item Limestone Networks, Inc. LIMES-2 400 S. Akard Street Suite 200 Dallas TX 75202 follow up this item ns2.freewebhostx.com follow up this item ns1.freewebhostx.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://danpshy.freewebhostx.com/test.txt ...
7 645680Report false positive Report closed case make a suggestion 2010-09-02 20:12:42     follow up this itemfollow up this contributor (sub5) as RSS-Feed sub5possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
22/39 (56,41%) 
 
PHP/Limworm.172478
PHP/C99Shell.I
PHP:C99Shell-F
PHP/BackDoor.C99Shell
Backdoor.PHP.ALI
HTM/C99shell.G
PHP.Shell-22
PHP.Shellbot.9
PHP/Shell.B
PHP/C99Shell.I
Backdoor.PHP.ALI
Backdoor.PHP.ALI
Backdoor.PHP.Agent
Backdoor
Backdoor.PHP.Agent.cr
Backdoor:PH 
 lookup in virustotal.com (fa62a9d1bdc10b9862aee9ea347846ad)-->[http://www.virustotal.com/file-scan/report.html?id=21f4bd5898211a126877d0eafdba11b7d4f7c71630eff8fc421047e60fdd5281-1283454225]follow up this md5sum(fa62a9d1bdc10b9862aee9ea347846ad)follow up this itemfollow up this virusname (PHP%2FLimworm.172478) as RSS-Feedlookup Virusname at avirafollow up this malware(PHP%2FLimworm.172478) for scanner (avira) in md5 table22/39 (56,41%) PHP/Limworm.172478
Safe Virus-Viewer and Analyser may take a minute to complete http://host67.hrwebservices.net/~allstag ...  up No previous evidence recordedSaved evidence (172458 Bytes) of last contact as txt September 02 2010 13:55:55 CEST. aliveSaved log of last contact as txt September 02 2010 21:02:18 CEST. SenderBaselookup 66.147.225.53 at Rus CERT university stuttgart germanylookup 66.147.225.53 at ARINfollow up this item(ip) in same window 66.147.225.53 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS4323) in networks tablefollow up this itemfollow up this AS (AS4323) as RSS-Feed AS4323 SenderBaselookup 66.147.225.53 at Rus CERT university stuttgart germanylookup 66.147.225.53 at ARINfollow up this item(review) in same window 66.147.225.53 Safe Virus-Viewer and Analyser may take a minute to complete http://host67.hrwebservices.net/~allstag ... follow up this domain(hrwebservices.net) hrwebservices.net follow up this itemfollow up this country (US) as RSS-Feed US follow up this itemfollow up this region (ARIN) as RSS-Feed ARIN follow up this itemfollow up this enail (john@hostrocket.com) as RSS-Feed john@hostrocket.com follow up this itemfollow up this item 66.147.224.0 - 66.147.239.255 follow up this item HRWEBSERVICES-2 follow up this item HostRocket Web Services HRWE 21 Corporate Drive - Suite 203 Clifton Park NY 12065 follow up this item dns1.hrnoc.net follow up this item dns2.hrnoc.net follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://host67.hrwebservices.net/~allstag ...
8 645685Report false positive Report closed case make a suggestion 2010-09-02 20:06:25     follow up this itemfollow up this contributor (sub5) as RSS-Feed sub5possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
21/39 (53,85%) 
 
PHP/Backdoor
PHP/Pbot.A
PHP/Pbot.A
PHP:Pbot-A
PHP/BackDoor.Q
Backdoor.PHP.Pbot.A
PHP.Bot
PHP.Shellbot.8
PHP/Phircbot.A
PHP/Pbot.A
Backdoor.PHP.Pbot.A
Backdoor.PHP.Pbot.A
Backdoor.PHP.Pbot
Trojan
Backdoor.PHP.Pbot.g
Backdoor:PHP/Phricbot.A
IRCBot.BCEL
Ma 
 lookup in virustotal.com (1f4e3791717b86fe6a994b6807586b5b)-->[http://www.virustotal.com/file-scan/report.html?id=33b5b033f33a059c281acdde3d622c4164ce1c22c607283ff89ce7b10f50cadf-1283454176]follow up this md5sum(1f4e3791717b86fe6a994b6807586b5b)follow up this itemfollow up this virusname (PHP%2FPbot.A) as RSS-Feedlookup Virusname at avirafollow up this malware(PHP%2FPbot.A) for scanner (avira) in md5 table21/39 (53,85%) PHP/Pbot.A
Safe Virus-Viewer and Analyser may take a minute to complete http://host67.hrwebservices.net/~allstag ...  up No previous evidence recordedSaved evidence (17408 Bytes) of last contact as txt September 02 2010 13:00:22 CEST. aliveSaved log of last contact as txt September 02 2010 21:02:06 CEST. SenderBaselookup 66.147.225.53 at Rus CERT university stuttgart germanylookup 66.147.225.53 at ARINfollow up this item(ip) in same window 66.147.225.53 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS4323) in networks tablefollow up this itemfollow up this AS (AS4323) as RSS-Feed AS4323 SenderBaselookup 66.147.225.53 at Rus CERT university stuttgart germanylookup 66.147.225.53 at ARINfollow up this item(review) in same window 66.147.225.53 Safe Virus-Viewer and Analyser may take a minute to complete http://host67.hrwebservices.net/~allstag ... follow up this domain(hrwebservices.net) hrwebservices.net follow up this itemfollow up this country (US) as RSS-Feed US follow up this itemfollow up this region (ARIN) as RSS-Feed ARIN follow up this itemfollow up this enail (john@hostrocket.com) as RSS-Feed john@hostrocket.com follow up this itemfollow up this item 66.147.224.0 - 66.147.239.255 follow up this item HRWEBSERVICES-2 follow up this item HostRocket Web Services HRWE 21 Corporate Drive - Suite 203 Clifton Park NY 12065 follow up this item dns2.hrnoc.net follow up this item dns1.hrnoc.net follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://host67.hrwebservices.net/~allstag ...
9 645647Report false positive Report closed case make a suggestion 2010-09-02 20:00:49     follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
Saved local log of joebox September 02 2010 21:43:20 CEST.8/39 (20,51%) 
 
ADSPY/Rozena.B
Trojan/Win32.Agent.gen
Suspicious:W32/Malware!Gemini
Virus.Downloader.Rozena
TrojanDownloader.Agent.cvwz
Trojan-Downloader.Win32.Agent.ehpd
Artemis!7ED890858813
Suspicious
file 
 lookup in virustotal.com (f06587355212447c8d3fe61f322ccaf7)-->[http://www.virustotal.com/file-scan/report.html?id=4293ee1dbda4f9eea5fa22886b7dbabc5ebaf549b97fafa7d4f26fa029c9acca-1283451122]lookup in threatexpert.comlookup the sha256(4293ee1dbda4f9eea5fa22886b7dbabc5ebaf549b97fafa7d4f26fa029c9acca) in comodo.comfollow up this md5sum(f06587355212447c8d3fe61f322ccaf7)follow up this itemfollow up this virusname (ADSPY%2FRozena.B) as RSS-Feedlookup Virusname at avirafollow up this malware(ADSPY%2FRozena.B) for scanner (avira) in md5 table8/39 (20,51%) ADSPY/Rozena.B
Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...  up No previous evidence recordedSaved evidence (1595144 Bytes) of last contact as txt August 26 2010 04:37:11 CEST. aliveSaved log of last contact as txt September 02 2010 20:09:21 CEST. SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(ip) in same window 58.253.235.84 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS17816) in networks tablefollow up this itemfollow up this AS (AS17816) as RSS-Feed AS17816 SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(review) in same window 58.253.235.84 Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ... follow up this domain(downxia.net) downxia.net follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@chinaunicom.cn) as RSS-Feed abuse@chinaunicom.cn follow up this itemfollow up this item 58.248.0.0 - 58.255.255.255 follow up this item UNICOM-GD follow up this item China Unicom Guangdong province networkChina UnicomCNC Group CHINA169 Guangdong Province Network follow up this item ns5.ename.net follow up this item ns2.ename.net follow up this item ns6.ename.net follow up this item ns3.ename.net follow up this item ns4.ename.net Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...
10 645648Report false positive Report closed case make a suggestion 2010-09-02 20:00:49     follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
Saved local log of joebox September 02 2010 21:40:14 CEST.8/39 (20,51%) 
 
ADSPY/Rozena.B
Trojan/Win32.Agent.gen
Suspicious:W32/Malware!Gemini
Virus.Downloader.Rozena
TrojanDownloader.Agent.cvwz
Trojan-Downloader.Win32.Agent.ehpd
Artemis!7ED890858813
Suspicious
file 
 lookup in virustotal.com (e9ea1f261d5e0475d5f625d4f425fd98)-->[http://www.virustotal.com/file-scan/report.html?id=24526a2f46b785616008166252fa207fd7ccfe7486ba20ff66f0e3deb8b29f1e-1283451002]lookup in threatexpert.comlookup the sha256(24526a2f46b785616008166252fa207fd7ccfe7486ba20ff66f0e3deb8b29f1e) in comodo.comfollow up this md5sum(e9ea1f261d5e0475d5f625d4f425fd98)follow up this itemfollow up this virusname (ADSPY%2FRozena.B) as RSS-Feedlookup Virusname at avirafollow up this malware(ADSPY%2FRozena.B) for scanner (avira) in md5 table8/39 (20,51%) ADSPY/Rozena.B
Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...  up No previous evidence recordedSaved evidence (1595088 Bytes) of last contact as txt August 26 2010 04:37:32 CEST. aliveSaved log of last contact as txt September 02 2010 20:09:00 CEST. SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(ip) in same window 58.253.235.84 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS17816) in networks tablefollow up this itemfollow up this AS (AS17816) as RSS-Feed AS17816 SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(review) in same window 58.253.235.84 Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ... follow up this domain(downxia.net) downxia.net follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@chinaunicom.cn) as RSS-Feed abuse@chinaunicom.cn follow up this itemfollow up this item 58.248.0.0 - 58.255.255.255 follow up this item UNICOM-GD follow up this item China Unicom Guangdong province networkChina UnicomCNC Group CHINA169 Guangdong Province Network follow up this item ns5.ename.net follow up this item ns2.ename.net follow up this item ns6.ename.net follow up this item ns3.ename.net follow up this item ns4.ename.net Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...
11 645649Report false positive Report closed case make a suggestion 2010-09-02 20:00:49     follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
Saved local log of joebox September 02 2010 21:36:44 CEST.8/38 (21,05%) 
 
ADSPY/Rozena.B
Trojan/Win32.Agent.gen
Suspicious:W32/Malware!Gemini
Virus.Downloader.Rozena
TrojanDownloader.Agent.cvwz
Trojan-Downloader.Win32.Agent.ehpd
Artemis!7ED890858813
Suspicious
file 
 lookup in virustotal.com (fd6374ba8e54adfb28274d4e9c3f8d7d)-->[http://www.virustotal.com/file-scan/report.html?id=9570c2ef86a347651c1e34dc45c8c2ffb73b543bc081a7016e1e7788f7ef064e-1283451068]lookup in threatexpert.comlookup the sha256(9570c2ef86a347651c1e34dc45c8c2ffb73b543bc081a7016e1e7788f7ef064e) in comodo.comfollow up this md5sum(fd6374ba8e54adfb28274d4e9c3f8d7d)follow up this itemfollow up this virusname (ADSPY%2FRozena.B) as RSS-Feedlookup Virusname at avirafollow up this malware(ADSPY%2FRozena.B) for scanner (avira) in md5 table8/38 (21,05%) ADSPY/Rozena.B
Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...  up No previous evidence recordedSaved evidence (1595136 Bytes) of last contact as txt August 26 2010 04:37:48 CEST. aliveSaved log of last contact as txt September 02 2010 20:08:42 CEST. SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(ip) in same window 58.253.235.84 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS17816) in networks tablefollow up this itemfollow up this AS (AS17816) as RSS-Feed AS17816 SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(review) in same window 58.253.235.84 Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ... follow up this domain(downxia.net) downxia.net follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@chinaunicom.cn) as RSS-Feed abuse@chinaunicom.cn follow up this itemfollow up this item 58.248.0.0 - 58.255.255.255 follow up this item UNICOM-GD follow up this item China Unicom Guangdong province networkChina UnicomCNC Group CHINA169 Guangdong Province Network follow up this item ns5.ename.net follow up this item ns2.ename.net follow up this item ns6.ename.net follow up this item ns3.ename.net follow up this item ns4.ename.net Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...
12 645650Report false positive Report closed case make a suggestion 2010-09-02 20:00:49     follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
Saved local log of joebox September 02 2010 21:33:12 CEST.8/39 (20,51%) 
 
ADSPY/Rozena.B
Trojan/Win32.Agent.gen
Suspicious:W32/Malware!Gemini
Virus.Downloader.Rozena
TrojanDownloader.Agent.cvwz
Trojan-Downloader.Win32.Agent.ehpd
Artemis!7ED890858813
Suspicious
file 
 lookup in virustotal.com (ec0e541c92d9541b9d8e34b4eab6aea1)-->[http://www.virustotal.com/file-scan/report.html?id=c48d0a233da3920ee5fa47a5764cb0b596799ae427bf75389c9eca6b4da6f678-1283450992]lookup in threatexpert.comlookup the sha256(c48d0a233da3920ee5fa47a5764cb0b596799ae427bf75389c9eca6b4da6f678) in comodo.comfollow up this md5sum(ec0e541c92d9541b9d8e34b4eab6aea1)follow up this itemfollow up this virusname (ADSPY%2FRozena.B) as RSS-Feedlookup Virusname at avirafollow up this malware(ADSPY%2FRozena.B) for scanner (avira) in md5 table8/39 (20,51%) ADSPY/Rozena.B
Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...  up No previous evidence recordedSaved evidence (1595152 Bytes) of last contact as txt August 26 2010 04:38:00 CEST. aliveSaved log of last contact as txt September 02 2010 20:08:24 CEST. SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(ip) in same window 58.253.235.84 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS17816) in networks tablefollow up this itemfollow up this AS (AS17816) as RSS-Feed AS17816 SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(review) in same window 58.253.235.84 Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ... follow up this domain(downxia.net) downxia.net follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@chinaunicom.cn) as RSS-Feed abuse@chinaunicom.cn follow up this itemfollow up this item 58.248.0.0 - 58.255.255.255 follow up this item UNICOM-GD follow up this item China Unicom Guangdong province networkChina UnicomCNC Group CHINA169 Guangdong Province Network follow up this item ns5.ename.net follow up this item ns2.ename.net follow up this item ns6.ename.net follow up this item ns3.ename.net follow up this item ns4.ename.net Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...
13 645651Report false positive Report closed case make a suggestion 2010-09-02 20:00:49     follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
Saved local log of joebox September 02 2010 21:29:44 CEST.8/39 (20,51%) 
 
ADSPY/Rozena.B
Trojan/Win32.Agent.gen
Suspicious:W32/Malware!Gemini
Virus.Downloader.Rozena
TrojanDownloader.Agent.cvwz
Trojan-Downloader.Win32.Agent.ehpd
Artemis!7ED890858813
Suspicious
file 
 lookup in virustotal.com (1ceed451487261161d272393c482bbbb)-->[http://www.virustotal.com/file-scan/report.html?id=97876a4c42b9427ed6fc7ce7fe60b847b305ee52fa5e3cf4e8b8008179d2f7b2-1283450968]lookup in threatexpert.comlookup the sha256(97876a4c42b9427ed6fc7ce7fe60b847b305ee52fa5e3cf4e8b8008179d2f7b2) in comodo.comfollow up this md5sum(1ceed451487261161d272393c482bbbb)follow up this itemfollow up this virusname (ADSPY%2FRozena.B) as RSS-Feedlookup Virusname at avirafollow up this malware(ADSPY%2FRozena.B) for scanner (avira) in md5 table8/39 (20,51%) ADSPY/Rozena.B
Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...  up No previous evidence recordedSaved evidence (1594912 Bytes) of last contact as txt August 26 2010 04:38:10 CEST. aliveSaved log of last contact as txt September 02 2010 20:08:02 CEST. SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(ip) in same window 58.253.235.84 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS17816) in networks tablefollow up this itemfollow up this AS (AS17816) as RSS-Feed AS17816 SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(review) in same window 58.253.235.84 Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ... follow up this domain(downxia.net) downxia.net follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@chinaunicom.cn) as RSS-Feed abuse@chinaunicom.cn follow up this itemfollow up this item 58.248.0.0 - 58.255.255.255 follow up this item UNICOM-GD follow up this item China Unicom Guangdong province networkChina UnicomCNC Group CHINA169 Guangdong Province Network follow up this item ns5.ename.net follow up this item ns2.ename.net follow up this item ns6.ename.net follow up this item ns3.ename.net follow up this item ns4.ename.net Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...
14 645652Report false positive Report closed case make a suggestion 2010-09-02 20:00:49     follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
Saved local log of joebox September 02 2010 21:26:14 CEST.8/38 (21,05%) 
 
ADSPY/Rozena.B
Trojan/Win32.Agent.gen
Suspicious:W32/Malware!Gemini
Virus.Downloader.Rozena
TrojanDownloader.Agent.cvwz
Trojan-Downloader.Win32.Agent.ehpd
Artemis!7ED890858813
Suspicious
file 
 lookup in virustotal.com (0d722ab7f9a0f1c1b70390b0b24f368f)-->[http://www.virustotal.com/file-scan/report.html?id=c071246fb2f094753b112a42c7df7346d9c4652062b7c3ef991d66810e07497b-1283451068]lookup in threatexpert.comlookup the sha256(c071246fb2f094753b112a42c7df7346d9c4652062b7c3ef991d66810e07497b) in comodo.comfollow up this md5sum(0d722ab7f9a0f1c1b70390b0b24f368f)follow up this itemfollow up this virusname (ADSPY%2FRozena.B) as RSS-Feedlookup Virusname at avirafollow up this malware(ADSPY%2FRozena.B) for scanner (avira) in md5 table8/38 (21,05%) ADSPY/Rozena.B
Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...  up No previous evidence recordedSaved evidence (1595160 Bytes) of last contact as txt August 26 2010 04:38:20 CEST. aliveSaved log of last contact as txt September 02 2010 20:07:48 CEST. SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(ip) in same window 58.253.235.84 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS17816) in networks tablefollow up this itemfollow up this AS (AS17816) as RSS-Feed AS17816 SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(review) in same window 58.253.235.84 Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ... follow up this domain(downxia.net) downxia.net follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@chinaunicom.cn) as RSS-Feed abuse@chinaunicom.cn follow up this itemfollow up this item 58.248.0.0 - 58.255.255.255 follow up this item UNICOM-GD follow up this item China Unicom Guangdong province networkChina UnicomCNC Group CHINA169 Guangdong Province Network follow up this item ns5.ename.net follow up this item ns2.ename.net follow up this item ns6.ename.net follow up this item ns3.ename.net follow up this item ns4.ename.net Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...
15 645653Report false positive Report closed case make a suggestion 2010-09-02 20:00:49     follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
Saved local log of joebox September 02 2010 21:22:44 CEST.8/39 (20,51%) 
 
ADSPY/Rozena.B
Trojan/Win32.Agent.gen
Suspicious:W32/Malware!Gemini
Virus.Downloader.Rozena
TrojanDownloader.Agent.cvwz
Trojan-Downloader.Win32.Agent.ehpd
Artemis!7ED890858813
Suspicious
file 
 lookup in virustotal.com (633d37b521b8bf59e1a0ba925b3eb9da)-->[http://www.virustotal.com/file-scan/report.html?id=bf75c7f29817ba6d0b15487fd39607677c9071808e5dca04b7234ae2b4232df2-1283450926]lookup in threatexpert.comlookup the sha256(bf75c7f29817ba6d0b15487fd39607677c9071808e5dca04b7234ae2b4232df2) in comodo.comfollow up this md5sum(633d37b521b8bf59e1a0ba925b3eb9da)follow up this itemfollow up this virusname (ADSPY%2FRozena.B) as RSS-Feedlookup Virusname at avirafollow up this malware(ADSPY%2FRozena.B) for scanner (avira) in md5 table8/39 (20,51%) ADSPY/Rozena.B
Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...  up No previous evidence recordedSaved evidence (1594944 Bytes) of last contact as txt August 26 2010 04:38:36 CEST. aliveSaved log of last contact as txt September 02 2010 20:07:32 CEST. SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(ip) in same window 58.253.235.84 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS17816) in networks tablefollow up this itemfollow up this AS (AS17816) as RSS-Feed AS17816 SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(review) in same window 58.253.235.84 Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ... follow up this domain(downxia.net) downxia.net follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@chinaunicom.cn) as RSS-Feed abuse@chinaunicom.cn follow up this itemfollow up this item 58.248.0.0 - 58.255.255.255 follow up this item UNICOM-GD follow up this item China Unicom Guangdong province networkChina UnicomCNC Group CHINA169 Guangdong Province Network follow up this item ns5.ename.net follow up this item ns2.ename.net follow up this item ns6.ename.net follow up this item ns3.ename.net follow up this item ns4.ename.net Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...
16 645654Report false positive Report closed case make a suggestion 2010-09-02 20:00:49     follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
Saved local log of joebox September 02 2010 21:19:38 CEST.8/39 (20,51%) 
 
ADSPY/Rozena.B
Trojan/Win32.Agent.gen
Suspicious:W32/Malware!Gemini
Virus.Downloader.Rozena
TrojanDownloader.Agent.cvwz
Trojan-Downloader.Win32.Agent.ehpd
Artemis!7ED890858813
Suspicious
file 
 lookup in virustotal.com (f9d9fdcd6523b736a64feeb6d00a5201)-->[http://www.virustotal.com/file-scan/report.html?id=0068891132ea90c730c0890c087ece01e0693e1d71c549f7c89dd3959bcdbb68-1283450939]lookup in threatexpert.comlookup the sha256(0068891132ea90c730c0890c087ece01e0693e1d71c549f7c89dd3959bcdbb68) in comodo.comfollow up this md5sum(f9d9fdcd6523b736a64feeb6d00a5201)follow up this itemfollow up this virusname (ADSPY%2FRozena.B) as RSS-Feedlookup Virusname at avirafollow up this malware(ADSPY%2FRozena.B) for scanner (avira) in md5 table8/39 (20,51%) ADSPY/Rozena.B
Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...  up No previous evidence recordedSaved evidence (1595160 Bytes) of last contact as txt August 26 2010 04:38:51 CEST. aliveSaved log of last contact as txt September 02 2010 20:07:16 CEST. SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(ip) in same window 58.253.235.84 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS17816) in networks tablefollow up this itemfollow up this AS (AS17816) as RSS-Feed AS17816 SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(review) in same window 58.253.235.84 Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ... follow up this domain(downxia.net) downxia.net follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@chinaunicom.cn) as RSS-Feed abuse@chinaunicom.cn follow up this itemfollow up this item 58.248.0.0 - 58.255.255.255 follow up this item UNICOM-GD follow up this item China Unicom Guangdong province networkChina UnicomCNC Group CHINA169 Guangdong Province Network follow up this item ns5.ename.net follow up this item ns2.ename.net follow up this item ns6.ename.net follow up this item ns3.ename.net follow up this item ns4.ename.net Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...
17 645655Report false positive Report closed case make a suggestion 2010-09-02 20:00:49     follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
Saved local log of joebox September 02 2010 21:16:16 CEST.8/39 (20,51%) 
 
ADSPY/Rozena.B
Trojan/Win32.Agent.gen
Suspicious:W32/Malware!Gemini
Virus.Downloader.Rozena
TrojanDownloader.Agent.cvwz
Trojan-Downloader.Win32.Agent.ehpd
Artemis!7ED890858813
Suspicious
file 
 lookup in virustotal.com (1e8f6c1a62f3b43dbffd9a5e0d98a106)-->[http://www.virustotal.com/file-scan/report.html?id=e06bfc83f78695426d372c5b735d45a2f0be6d5e1be242defe8c92d0f37a7275-1283450893]lookup in threatexpert.comlookup the sha256(e06bfc83f78695426d372c5b735d45a2f0be6d5e1be242defe8c92d0f37a7275) in comodo.comfollow up this md5sum(1e8f6c1a62f3b43dbffd9a5e0d98a106)follow up this itemfollow up this virusname (ADSPY%2FRozena.B) as RSS-Feedlookup Virusname at avirafollow up this malware(ADSPY%2FRozena.B) for scanner (avira) in md5 table8/39 (20,51%) ADSPY/Rozena.B
Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...  up No previous evidence recordedSaved evidence (1595168 Bytes) of last contact as txt August 26 2010 04:39:05 CEST. aliveSaved log of last contact as txt September 02 2010 20:07:00 CEST. SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(ip) in same window 58.253.235.84 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS17816) in networks tablefollow up this itemfollow up this AS (AS17816) as RSS-Feed AS17816 SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(review) in same window 58.253.235.84 Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ... follow up this domain(downxia.net) downxia.net follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@chinaunicom.cn) as RSS-Feed abuse@chinaunicom.cn follow up this itemfollow up this item 58.248.0.0 - 58.255.255.255 follow up this item UNICOM-GD follow up this item China Unicom Guangdong province networkChina UnicomCNC Group CHINA169 Guangdong Province Network follow up this item ns5.ename.net follow up this item ns2.ename.net follow up this item ns6.ename.net follow up this item ns3.ename.net follow up this item ns4.ename.net Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...
18 645656Report false positive Report closed case make a suggestion 2010-09-02 20:00:49     follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
Saved local log of joebox September 02 2010 21:12:36 CEST.8/39 (20,51%) 
 
ADSPY/Rozena.B
Trojan/Win32.Agent.gen
Suspicious:W32/Malware!Gemini
Virus.Downloader.Rozena
TrojanDownloader.Agent.cvwz
Trojan-Downloader.Win32.Agent.ehpd
Artemis!7ED890858813
Suspicious
file 
 lookup in virustotal.com (b7b0825d53334f290f6eaa054cb0f5b1)-->[http://www.virustotal.com/file-scan/report.html?id=d0a9480e24d0b1b397d2921c2af2394f5f4cdeffca050d25cb902d5e0c39007a-1283450956]lookup in threatexpert.comlookup the sha256(d0a9480e24d0b1b397d2921c2af2394f5f4cdeffca050d25cb902d5e0c39007a) in comodo.comfollow up this md5sum(b7b0825d53334f290f6eaa054cb0f5b1)follow up this itemfollow up this virusname (ADSPY%2FRozena.B) as RSS-Feedlookup Virusname at avirafollow up this malware(ADSPY%2FRozena.B) for scanner (avira) in md5 table8/39 (20,51%) ADSPY/Rozena.B
Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...  up No previous evidence recordedSaved evidence (1595040 Bytes) of last contact as txt August 26 2010 04:39:19 CEST. aliveSaved log of last contact as txt September 02 2010 20:06:43 CEST. SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(ip) in same window 58.253.235.84 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS17816) in networks tablefollow up this itemfollow up this AS (AS17816) as RSS-Feed AS17816 SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(review) in same window 58.253.235.84 Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ... follow up this domain(downxia.net) downxia.net follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@chinaunicom.cn) as RSS-Feed abuse@chinaunicom.cn follow up this itemfollow up this item 58.248.0.0 - 58.255.255.255 follow up this item UNICOM-GD follow up this item China Unicom Guangdong province networkChina UnicomCNC Group CHINA169 Guangdong Province Network follow up this item ns5.ename.net follow up this item ns2.ename.net follow up this item ns6.ename.net follow up this item ns3.ename.net follow up this item ns4.ename.net Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...
19 645657Report false positive Report closed case make a suggestion 2010-09-02 20:00:49     follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
Saved local log of joebox September 02 2010 21:09:08 CEST.8/39 (20,51%) 
 
ADSPY/Rozena.B
Trojan/Win32.Agent.gen
Suspicious:W32/Malware!Gemini
Virus.Downloader.Rozena
TrojanDownloader.Agent.cvwz
Trojan-Downloader.Win32.Agent.ehpd
Artemis!7ED890858813
Suspicious
file 
 lookup in virustotal.com (dcf4f8155f093fa29203081a388575cd)-->[http://www.virustotal.com/file-scan/report.html?id=731a639e1462ee8b5c212a28774f4125430111f9bf865ffa67a7c9c82e3961b4-1283450862]lookup in threatexpert.comlookup the sha256(731a639e1462ee8b5c212a28774f4125430111f9bf865ffa67a7c9c82e3961b4) in comodo.comfollow up this md5sum(dcf4f8155f093fa29203081a388575cd)follow up this itemfollow up this virusname (ADSPY%2FRozena.B) as RSS-Feedlookup Virusname at avirafollow up this malware(ADSPY%2FRozena.B) for scanner (avira) in md5 table8/39 (20,51%) ADSPY/Rozena.B
Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...  up No previous evidence recordedSaved evidence (1595032 Bytes) of last contact as txt August 26 2010 04:39:40 CEST. aliveSaved log of last contact as txt September 02 2010 20:06:28 CEST. SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(ip) in same window 58.253.235.84 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS17816) in networks tablefollow up this itemfollow up this AS (AS17816) as RSS-Feed AS17816 SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(review) in same window 58.253.235.84 Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ... follow up this domain(downxia.net) downxia.net follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@chinaunicom.cn) as RSS-Feed abuse@chinaunicom.cn follow up this itemfollow up this item 58.248.0.0 - 58.255.255.255 follow up this item UNICOM-GD follow up this item China Unicom Guangdong province networkChina UnicomCNC Group CHINA169 Guangdong Province Network follow up this item ns5.ename.net follow up this item ns2.ename.net follow up this item ns6.ename.net follow up this item ns3.ename.net follow up this item ns4.ename.net Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...
20 645658Report false positive Report closed case make a suggestion 2010-09-02 20:00:49     follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
Saved local log of joebox September 02 2010 21:05:44 CEST.7/38 (18,42%) 
 
ADSPY/Rozena.B
Trojan/Win32.Agent.gen
Suspicious:W32/Malware!Gemini
Virus.Downloader.Rozena
TrojanDownloader.Agent.cvwz
Trojan-Downloader.Win32.Agent.ehpd
Suspicious
file 
 lookup in virustotal.com (108108da13e726d49e917a745ef91e32)-->[http://www.virustotal.com/file-scan/report.html?id=6243558b11f3f3da3cf41f1ef5431d0f1a0094635c7ace00e4832865deb5a9e1-1283450885]lookup in threatexpert.comlookup the sha256(6243558b11f3f3da3cf41f1ef5431d0f1a0094635c7ace00e4832865deb5a9e1) in comodo.comfollow up this md5sum(108108da13e726d49e917a745ef91e32)follow up this itemfollow up this virusname (ADSPY%2FRozena.B) as RSS-Feedlookup Virusname at avirafollow up this malware(ADSPY%2FRozena.B) for scanner (avira) in md5 table7/38 (18,42%) ADSPY/Rozena.B
Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...  up No previous evidence recordedSaved evidence (1595056 Bytes) of last contact as txt August 26 2010 04:39:51 CEST. aliveSaved log of last contact as txt September 02 2010 20:06:11 CEST. SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(ip) in same window 58.253.235.84 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS17816) in networks tablefollow up this itemfollow up this AS (AS17816) as RSS-Feed AS17816 SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(review) in same window 58.253.235.84 Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ... follow up this domain(downxia.net) downxia.net follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@chinaunicom.cn) as RSS-Feed abuse@chinaunicom.cn follow up this itemfollow up this item 58.248.0.0 - 58.255.255.255 follow up this item UNICOM-GD follow up this item China Unicom Guangdong province networkChina UnicomCNC Group CHINA169 Guangdong Province Network follow up this item ns5.ename.net follow up this item ns2.ename.net follow up this item ns6.ename.net follow up this item ns3.ename.net follow up this item ns4.ename.net Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...
21 645659Report false positive Report closed case make a suggestion 2010-09-02 20:00:49     follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
Saved local log of joebox September 02 2010 21:02:12 CEST.8/39 (20,51%) 
 
ADSPY/Rozena.B
Trojan/Win32.Agent.gen
Suspicious:W32/Malware!Gemini
Virus.Downloader.Rozena
TrojanDownloader.Agent.cvwz
Trojan-Downloader.Win32.Agent.ehpd
Artemis!7ED890858813
Suspicious
file 
 lookup in virustotal.com (2af23b883ff1a66459463b7af7ca8563)-->[http://www.virustotal.com/file-scan/report.html?id=00e947e7711365aa064a9c59a2e97d84672b99b1e8ec8157ecb55e8ac43451dd-1283450880]lookup in threatexpert.comlookup the sha256(00e947e7711365aa064a9c59a2e97d84672b99b1e8ec8157ecb55e8ac43451dd) in comodo.comfollow up this md5sum(2af23b883ff1a66459463b7af7ca8563)follow up this itemfollow up this virusname (ADSPY%2FRozena.B) as RSS-Feedlookup Virusname at avirafollow up this malware(ADSPY%2FRozena.B) for scanner (avira) in md5 table8/39 (20,51%) ADSPY/Rozena.B
Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...  up No previous evidence recordedSaved evidence (1594992 Bytes) of last contact as txt August 26 2010 04:40:08 CEST. aliveSaved log of last contact as txt September 02 2010 20:05:52 CEST. SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(ip) in same window 58.253.235.84 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS17816) in networks tablefollow up this itemfollow up this AS (AS17816) as RSS-Feed AS17816 SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(review) in same window 58.253.235.84 Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ... follow up this domain(downxia.net) downxia.net follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@chinaunicom.cn) as RSS-Feed abuse@chinaunicom.cn follow up this itemfollow up this item 58.248.0.0 - 58.255.255.255 follow up this item UNICOM-GD follow up this item China Unicom Guangdong province networkChina UnicomCNC Group CHINA169 Guangdong Province Network follow up this item ns5.ename.net follow up this item ns2.ename.net follow up this item ns6.ename.net follow up this item ns3.ename.net follow up this item ns4.ename.net Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...
22 645660Report false positive Report closed case make a suggestion 2010-09-02 20:00:49     follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
Saved local log of joebox September 02 2010 20:59:06 CEST.8/39 (20,51%) 
 
ADSPY/Rozena.B
Trojan/Win32.Agent.gen
Suspicious:W32/Malware!Gemini
Virus.Downloader.Rozena
TrojanDownloader.Agent.cvwz
Trojan-Downloader.Win32.Agent.ehpd
Artemis!7ED890858813
Suspicious
file 
 lookup in virustotal.com (997da1fb3b5a2b7f82932ba68392b1eb)-->[http://www.virustotal.com/file-scan/report.html?id=9bd4e4436260be8ba1f55c3c208e838925e6243f12e9a7d464b3761f2739fa40-1283450941]lookup in threatexpert.comlookup the sha256(9bd4e4436260be8ba1f55c3c208e838925e6243f12e9a7d464b3761f2739fa40) in comodo.comfollow up this md5sum(997da1fb3b5a2b7f82932ba68392b1eb)follow up this itemfollow up this virusname (ADSPY%2FRozena.B) as RSS-Feedlookup Virusname at avirafollow up this malware(ADSPY%2FRozena.B) for scanner (avira) in md5 table8/39 (20,51%) ADSPY/Rozena.B
Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...  up No previous evidence recordedSaved evidence (1595040 Bytes) of last contact as txt August 26 2010 04:40:17 CEST. aliveSaved log of last contact as txt September 02 2010 20:05:37 CEST. SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(ip) in same window 58.253.235.84 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS17816) in networks tablefollow up this itemfollow up this AS (AS17816) as RSS-Feed AS17816 SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(review) in same window 58.253.235.84 Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ... follow up this domain(downxia.net) downxia.net follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@chinaunicom.cn) as RSS-Feed abuse@chinaunicom.cn follow up this itemfollow up this item 58.248.0.0 - 58.255.255.255 follow up this item UNICOM-GD follow up this item China Unicom Guangdong province networkChina UnicomCNC Group CHINA169 Guangdong Province Network follow up this item ns5.ename.net follow up this item ns2.ename.net follow up this item ns6.ename.net follow up this item ns3.ename.net follow up this item ns4.ename.net Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...
23 645661Report false positive Report closed case make a suggestion 2010-09-02 20:00:49     follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
Saved local log of joebox September 02 2010 20:55:42 CEST.8/39 (20,51%) 
 
ADSPY/Rozena.B
Trojan/Win32.Agent.gen
Suspicious:W32/Malware!Gemini
Virus.Downloader.Rozena
TrojanDownloader.Agent.cvwz
Trojan-Downloader.Win32.Agent.ehpd
Artemis!7ED890858813
Suspicious
file 
 lookup in virustotal.com (1550970585670905a62c8cdc4f7c0727)-->[http://www.virustotal.com/file-scan/report.html?id=44a6e942ab15f2e66746993857c207ac2bd71ba29e2f38b578b20be9876d15ff-1283451286]lookup in threatexpert.comlookup the sha256(44a6e942ab15f2e66746993857c207ac2bd71ba29e2f38b578b20be9876d15ff) in comodo.comfollow up this md5sum(1550970585670905a62c8cdc4f7c0727)follow up this itemfollow up this virusname (ADSPY%2FRozena.B) as RSS-Feedlookup Virusname at avirafollow up this malware(ADSPY%2FRozena.B) for scanner (avira) in md5 table8/39 (20,51%) ADSPY/Rozena.B
Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...  up No previous evidence recordedSaved evidence (1594760 Bytes) of last contact as txt August 26 2010 04:40:29 CEST. aliveSaved log of last contact as txt September 02 2010 20:05:21 CEST. SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(ip) in same window 58.253.235.84 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS17816) in networks tablefollow up this itemfollow up this AS (AS17816) as RSS-Feed AS17816 SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(review) in same window 58.253.235.84 Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ... follow up this domain(downxia.net) downxia.net follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@chinaunicom.cn) as RSS-Feed abuse@chinaunicom.cn follow up this itemfollow up this item 58.248.0.0 - 58.255.255.255 follow up this item UNICOM-GD follow up this item China Unicom Guangdong province networkChina UnicomCNC Group CHINA169 Guangdong Province Network follow up this item ns5.ename.net follow up this item ns2.ename.net follow up this item ns6.ename.net follow up this item ns3.ename.net follow up this item ns4.ename.net Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...
24 645662Report false positive Report closed case make a suggestion 2010-09-02 20:00:49     follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
Saved local log of joebox September 02 2010 20:52:26 CEST.8/39 (20,51%) 
 
ADSPY/Rozena.B
Trojan/Win32.Agent.gen
Suspicious:W32/Malware!Gemini
Virus.Downloader.Rozena
TrojanDownloader.Agent.cvwz
Trojan-Downloader.Win32.Agent.ehpd
Artemis!7ED890858813
Suspicious
file 
 lookup in virustotal.com (c5bfe272ebd3ba95a2e0ba04f65a320c)-->[http://www.virustotal.com/file-scan/report.html?id=c88b2d1dbeb71862c7aa4134856375d2534a98a91808de93df9ff1902bf172e4-1283450861]lookup in threatexpert.comlookup the sha256(c88b2d1dbeb71862c7aa4134856375d2534a98a91808de93df9ff1902bf172e4) in comodo.comfollow up this md5sum(c5bfe272ebd3ba95a2e0ba04f65a320c)follow up this itemfollow up this virusname (ADSPY%2FRozena.B) as RSS-Feedlookup Virusname at avirafollow up this malware(ADSPY%2FRozena.B) for scanner (avira) in md5 table8/39 (20,51%) ADSPY/Rozena.B
Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...  up No previous evidence recordedSaved evidence (1583864 Bytes) of last contact as txt August 26 2010 04:40:38 CEST. aliveSaved log of last contact as txt September 02 2010 20:05:07 CEST. SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(ip) in same window 58.253.235.84 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS17816) in networks tablefollow up this itemfollow up this AS (AS17816) as RSS-Feed AS17816 SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(review) in same window 58.253.235.84 Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ... follow up this domain(downxia.net) downxia.net follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@chinaunicom.cn) as RSS-Feed abuse@chinaunicom.cn follow up this itemfollow up this item 58.248.0.0 - 58.255.255.255 follow up this item UNICOM-GD follow up this item China Unicom Guangdong province networkChina UnicomCNC Group CHINA169 Guangdong Province Network follow up this item ns5.ename.net follow up this item ns2.ename.net follow up this item ns6.ename.net follow up this item ns3.ename.net follow up this item ns4.ename.net Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...
25 645663Report false positive Report closed case make a suggestion 2010-09-02 20:00:49     follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
Saved local log of joebox September 02 2010 20:50:06 CEST.9/39 (23,08%) 
 
ADSPY/Rozena.B
Trojan/Win32.Agent.gen
TrojWare.Win32.TrojanDownloader.Delf.AOQ0
Suspicious:W32/Malware!Gemini
Virus.Downloader.Rozena
TrojanDownloader.Agent.cvwz
Trojan-Downloader.Win32.Agent.ehpd
Artemis!7ED890858813
Suspicious
file 
 lookup in virustotal.com (683ba7d18e45cb029b8fdb69fecb927f)-->[http://www.virustotal.com/file-scan/report.html?id=f3db521c64406b1e9a7454de052c86aa8aa5a2559409059236067d958f088431-1283451275]lookup in threatexpert.comlookup the sha256(f3db521c64406b1e9a7454de052c86aa8aa5a2559409059236067d958f088431) in comodo.comfollow up this md5sum(683ba7d18e45cb029b8fdb69fecb927f)follow up this itemfollow up this virusname (ADSPY%2FRozena.B) as RSS-Feedlookup Virusname at avirafollow up this malware(ADSPY%2FRozena.B) for scanner (avira) in md5 table9/39 (23,08%) ADSPY/Rozena.B
Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...  up No previous evidence recordedSaved evidence (1606488 Bytes) of last contact as txt August 26 2010 04:40:52 CEST. aliveSaved log of last contact as txt September 02 2010 20:04:51 CEST. SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(ip) in same window 58.253.235.84 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS17816) in networks tablefollow up this itemfollow up this AS (AS17816) as RSS-Feed AS17816 SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(review) in same window 58.253.235.84 Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ... follow up this domain(downxia.net) downxia.net follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@chinaunicom.cn) as RSS-Feed abuse@chinaunicom.cn follow up this itemfollow up this item 58.248.0.0 - 58.255.255.255 follow up this item UNICOM-GD follow up this item China Unicom Guangdong province networkChina UnicomCNC Group CHINA169 Guangdong Province Network follow up this item ns5.ename.net follow up this item ns2.ename.net follow up this item ns6.ename.net follow up this item ns3.ename.net follow up this item ns4.ename.net Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...
helpLine help#descendigascending helpDatedescendigascending helpCloseddescendigascending helphours helpcontributordescendigascending helpvirusnamedescendigascending helpURLdescendigascending helpip state helpresponsedescendigascending helpIp initialdescendigascending helpAS#descendigascending helpip reviewdescendigascending helpURLdescendigascending helpDomaindescendigascending helpcountrydescendigascending helpsourcedescendigascending helpemaildescendigascending helpinetnumdescendigascending helpnetnamedescendigascending helpdescrdescendigascending helpns1descendigascending helpns2descendigascending helpns3descendigascending helpns4descendigascending helpns5descendigascending helpURLdescendigascending
26 645664Report false positive Report closed case make a suggestion 2010-09-02 20:00:49     follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
Saved local log of joebox September 02 2010 20:46:42 CEST.8/39 (20,51%) 
 
ADSPY/Rozena.B
Trojan/Win32.Agent.gen
Suspicious:W32/Malware!Gemini
Virus.Downloader.Rozena
TrojanDownloader.Agent.cvwz
Trojan-Downloader.Win32.Agent.ehpd
Artemis!7ED890858813
Suspicious
file 
 lookup in virustotal.com (b2fc4acda7e70533858a2f15136cb76c)-->[http://www.virustotal.com/file-scan/report.html?id=635afa73ec1a341934e2ca6081582bf182b3feeee1079457e6886b5891ad2eb2-1283450953]lookup in threatexpert.comlookup the sha256(635afa73ec1a341934e2ca6081582bf182b3feeee1079457e6886b5891ad2eb2) in comodo.comfollow up this md5sum(b2fc4acda7e70533858a2f15136cb76c)follow up this itemfollow up this virusname (ADSPY%2FRozena.B) as RSS-Feedlookup Virusname at avirafollow up this malware(ADSPY%2FRozena.B) for scanner (avira) in md5 table8/39 (20,51%) ADSPY/Rozena.B
Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...  up No previous evidence recordedSaved evidence (1583608 Bytes) of last contact as txt August 26 2010 04:41:02 CEST. aliveSaved log of last contact as txt September 02 2010 20:04:37 CEST. SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(ip) in same window 58.253.235.84 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS17816) in networks tablefollow up this itemfollow up this AS (AS17816) as RSS-Feed AS17816 SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(review) in same window 58.253.235.84 Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ... follow up this domain(downxia.net) downxia.net follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@chinaunicom.cn) as RSS-Feed abuse@chinaunicom.cn follow up this itemfollow up this item 58.248.0.0 - 58.255.255.255 follow up this item UNICOM-GD follow up this item China Unicom Guangdong province networkChina UnicomCNC Group CHINA169 Guangdong Province Network follow up this item ns5.ename.net follow up this item ns2.ename.net follow up this item ns6.ename.net follow up this item ns3.ename.net follow up this item ns4.ename.net Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...
27 645665Report false positive Report closed case make a suggestion 2010-09-02 20:00:49     follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
Saved local log of joebox September 02 2010 20:42:58 CEST.9/39 (23,08%) 
 
ADSPY/Rozena.B
Trojan/Win32.Agent.gen
TrojWare.Win32.TrojanDownloader.Delf.AOQ0
Suspicious:W32/Malware!Gemini
Virus.Downloader.Rozena
TrojanDownloader.Agent.cvwz
Trojan-Downloader.Win32.Agent.ehpd
Artemis!7ED890858813
Suspicious
file 
 lookup in virustotal.com (f5f8c68917fb2d33f2d6ece117cacc7f)-->[http://www.virustotal.com/file-scan/report.html?id=383bcea788db9683684df11fdcd21d34e10a1918a28981cb4cf3bfebad62f5d6-1283451280]lookup in threatexpert.comlookup the sha256(383bcea788db9683684df11fdcd21d34e10a1918a28981cb4cf3bfebad62f5d6) in comodo.comfollow up this md5sum(f5f8c68917fb2d33f2d6ece117cacc7f)follow up this itemfollow up this virusname (ADSPY%2FRozena.B) as RSS-Feedlookup Virusname at avirafollow up this malware(ADSPY%2FRozena.B) for scanner (avira) in md5 table9/39 (23,08%) ADSPY/Rozena.B
Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...  up No previous evidence recordedSaved evidence (1609304 Bytes) of last contact as txt August 26 2010 04:41:10 CEST. aliveSaved log of last contact as txt September 02 2010 20:04:22 CEST. SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(ip) in same window 58.253.235.84 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS17816) in networks tablefollow up this itemfollow up this AS (AS17816) as RSS-Feed AS17816 SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(review) in same window 58.253.235.84 Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ... follow up this domain(downxia.net) downxia.net follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@chinaunicom.cn) as RSS-Feed abuse@chinaunicom.cn follow up this itemfollow up this item 58.248.0.0 - 58.255.255.255 follow up this item UNICOM-GD follow up this item China Unicom Guangdong province networkChina UnicomCNC Group CHINA169 Guangdong Province Network follow up this item ns5.ename.net follow up this item ns2.ename.net follow up this item ns6.ename.net follow up this item ns3.ename.net follow up this item ns4.ename.net Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...
28 645666Report false positive Report closed case make a suggestion 2010-09-02 20:00:49     follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
Saved local log of joebox September 02 2010 20:39:20 CEST.9/39 (23,08%) 
 
ADSPY/Rozena.B
Trojan/Win32.Agent.gen
TrojWare.Win32.TrojanDownloader.Delf.AOQ0
Suspicious:W32/Malware!Gemini
Virus.Downloader.Rozena
TrojanDownloader.Agent.cvwz
Trojan-Downloader.Win32.Agent.ehpd
Artemis!7ED890858813
Suspicious
file 
 lookup in virustotal.com (9c15e330a49196fa5e6fefac93d3e3e1)-->[http://www.virustotal.com/file-scan/report.html?id=36eced79d7f9360485e497735b38e39ace5ef0ceedf38e13460dd8c9f7a96712-1283450844]lookup in threatexpert.comlookup the sha256(36eced79d7f9360485e497735b38e39ace5ef0ceedf38e13460dd8c9f7a96712) in comodo.comfollow up this md5sum(9c15e330a49196fa5e6fefac93d3e3e1)follow up this itemfollow up this virusname (ADSPY%2FRozena.B) as RSS-Feedlookup Virusname at avirafollow up this malware(ADSPY%2FRozena.B) for scanner (avira) in md5 table9/39 (23,08%) ADSPY/Rozena.B
Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...  up No previous evidence recordedSaved evidence (1609440 Bytes) of last contact as txt August 26 2010 04:41:20 CEST. aliveSaved log of last contact as txt September 02 2010 20:04:03 CEST. SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(ip) in same window 58.253.235.84 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS17816) in networks tablefollow up this itemfollow up this AS (AS17816) as RSS-Feed AS17816 SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(review) in same window 58.253.235.84 Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ... follow up this domain(downxia.net) downxia.net follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@chinaunicom.cn) as RSS-Feed abuse@chinaunicom.cn follow up this itemfollow up this item 58.248.0.0 - 58.255.255.255 follow up this item UNICOM-GD follow up this item China Unicom Guangdong province networkChina UnicomCNC Group CHINA169 Guangdong Province Network follow up this item ns5.ename.net follow up this item ns2.ename.net follow up this item ns6.ename.net follow up this item ns3.ename.net follow up this item ns4.ename.net Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...
29 645667Report false positive Report closed case make a suggestion 2010-09-02 20:00:49     follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
Saved local log of joebox September 02 2010 20:35:54 CEST.9/39 (23,08%) 
 
ADSPY/Rozena.B
Trojan/Win32.Agent.gen
TrojWare.Win32.TrojanDownloader.Delf.AOQ0
Suspicious:W32/Malware!Gemini
Virus.Downloader.Rozena
TrojanDownloader.Agent.cvwz
Trojan-Downloader.Win32.Agent.ehpd
Artemis!7ED890858813
Suspicious
file 
 lookup in virustotal.com (d63d6502a8e868dd0896bab0dad31eb9)-->[http://www.virustotal.com/file-scan/report.html?id=f076e51bacff7c9d6c65f88bbe6bc78195224f44a5352d67efc94826f1b2bd1d-1283450891]lookup in threatexpert.comlookup the sha256(f076e51bacff7c9d6c65f88bbe6bc78195224f44a5352d67efc94826f1b2bd1d) in comodo.comfollow up this md5sum(d63d6502a8e868dd0896bab0dad31eb9)follow up this itemfollow up this virusname (ADSPY%2FRozena.B) as RSS-Feedlookup Virusname at avirafollow up this malware(ADSPY%2FRozena.B) for scanner (avira) in md5 table9/39 (23,08%) ADSPY/Rozena.B
Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...  up No previous evidence recordedSaved evidence (1609288 Bytes) of last contact as txt August 26 2010 04:41:28 CEST. aliveSaved log of last contact as txt September 02 2010 20:03:48 CEST. SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(ip) in same window 58.253.235.84 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS17816) in networks tablefollow up this itemfollow up this AS (AS17816) as RSS-Feed AS17816 SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(review) in same window 58.253.235.84 Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ... follow up this domain(downxia.net) downxia.net follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@chinaunicom.cn) as RSS-Feed abuse@chinaunicom.cn follow up this itemfollow up this item 58.248.0.0 - 58.255.255.255 follow up this item UNICOM-GD follow up this item China Unicom Guangdong province networkChina UnicomCNC Group CHINA169 Guangdong Province Network follow up this item ns5.ename.net follow up this item ns2.ename.net follow up this item ns6.ename.net follow up this item ns3.ename.net follow up this item ns4.ename.net Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...
30 645668Report false positive Report closed case make a suggestion 2010-09-02 20:00:49     follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
Saved local log of joebox September 02 2010 20:31:48 CEST.8/39 (20,51%) 
 
ADSPY/Rozena.B
Trojan/Win32.Agent.gen
Suspicious:W32/Malware!Gemini
Virus.Downloader.Rozena
TrojanDownloader.Agent.cvwz
Trojan-Downloader.Win32.Agent.ehpd
Artemis!7ED890858813
Suspicious
file 
 lookup in virustotal.com (5feaf4664afb1af84ba010fabd454b44)-->[http://www.virustotal.com/file-scan/report.html?id=77c4f96b99880216622a9dc6d8abfb0e73aab1ffdcc565bf9148f8e8ffd51534-1283450815]lookup in threatexpert.comlookup the sha256(77c4f96b99880216622a9dc6d8abfb0e73aab1ffdcc565bf9148f8e8ffd51534) in comodo.comfollow up this md5sum(5feaf4664afb1af84ba010fabd454b44)follow up this itemfollow up this virusname (ADSPY%2FRozena.B) as RSS-Feedlookup Virusname at avirafollow up this malware(ADSPY%2FRozena.B) for scanner (avira) in md5 table8/39 (20,51%) ADSPY/Rozena.B
Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...  up No previous evidence recordedSaved evidence (1583776 Bytes) of last contact as txt August 26 2010 04:41:37 CEST. aliveSaved log of last contact as txt September 02 2010 20:03:25 CEST. SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(ip) in same window 58.253.235.84 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS17816) in networks tablefollow up this itemfollow up this AS (AS17816) as RSS-Feed AS17816 SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(review) in same window 58.253.235.84 Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ... follow up this domain(downxia.net) downxia.net follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@chinaunicom.cn) as RSS-Feed abuse@chinaunicom.cn follow up this itemfollow up this item 58.248.0.0 - 58.255.255.255 follow up this item UNICOM-GD follow up this item China Unicom Guangdong province networkChina UnicomCNC Group CHINA169 Guangdong Province Network follow up this item ns5.ename.net follow up this item ns2.ename.net follow up this item ns6.ename.net follow up this item ns3.ename.net follow up this item ns4.ename.net Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...
31 645669Report false positive Report closed case make a suggestion 2010-09-02 20:00:49     follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
Saved local log of joebox September 02 2010 20:27:54 CEST.9/39 (23,08%) 
 
ADSPY/Rozena.B
Trojan/Win32.Agent.gen
TrojWare.Win32.TrojanDownloader.Delf.AOQ0
Suspicious:W32/Malware!Gemini
Virus.Downloader.Rozena
TrojanDownloader.Agent.cvwz
Trojan-Downloader.Win32.Agent.ehpd
Artemis!7ED890858813
Suspicious
file 
 lookup in virustotal.com (1d3b1333a656ebd5901b7c04bf1b192d)-->[http://www.virustotal.com/file-scan/report.html?id=f185ad84407867df31ba9aca7249b72b88cf9dc61a4a6856f6a2c619e8daa33e-1283450699]lookup in threatexpert.comlookup the sha256(f185ad84407867df31ba9aca7249b72b88cf9dc61a4a6856f6a2c619e8daa33e) in comodo.comfollow up this md5sum(1d3b1333a656ebd5901b7c04bf1b192d)follow up this itemfollow up this virusname (ADSPY%2FRozena.B) as RSS-Feedlookup Virusname at avirafollow up this malware(ADSPY%2FRozena.B) for scanner (avira) in md5 table9/39 (23,08%) ADSPY/Rozena.B
Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...  up No previous evidence recordedSaved evidence (1609568 Bytes) of last contact as txt August 26 2010 04:41:56 CEST. aliveSaved log of last contact as txt September 02 2010 20:03:06 CEST. SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(ip) in same window 58.253.235.84 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS17816) in networks tablefollow up this itemfollow up this AS (AS17816) as RSS-Feed AS17816 SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(review) in same window 58.253.235.84 Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ... follow up this domain(downxia.net) downxia.net follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@chinaunicom.cn) as RSS-Feed abuse@chinaunicom.cn follow up this itemfollow up this item 58.248.0.0 - 58.255.255.255 follow up this item UNICOM-GD follow up this item China Unicom Guangdong province networkChina UnicomCNC Group CHINA169 Guangdong Province Network follow up this item ns5.ename.net follow up this item ns2.ename.net follow up this item ns6.ename.net follow up this item ns3.ename.net follow up this item ns4.ename.net Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...
32 645670Report false positive Report closed case make a suggestion 2010-09-02 20:00:49     follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
Saved local log of joebox September 02 2010 20:24:14 CEST.9/39 (23,08%) 
 
ADSPY/Rozena.B
Trojan/Win32.Agent.gen
TrojWare.Win32.TrojanDownloader.Delf.AOQ0
Suspicious:W32/Malware!Gemini
Virus.Downloader.Rozena
TrojanDownloader.Agent.cvwz
Trojan-Downloader.Win32.Agent.ehpd
Artemis!7ED890858813
Suspicious
file 
 lookup in virustotal.com (9052f26ac3b54f8136272f632dca2fbf)-->[http://www.virustotal.com/file-scan/report.html?id=816fc794ba797f529abadbadc3af0c67179887916b0cefedba7f4a539844c832-1283450655]lookup in threatexpert.comlookup the sha256(816fc794ba797f529abadbadc3af0c67179887916b0cefedba7f4a539844c832) in comodo.comfollow up this md5sum(9052f26ac3b54f8136272f632dca2fbf)follow up this itemfollow up this virusname (ADSPY%2FRozena.B) as RSS-Feedlookup Virusname at avirafollow up this malware(ADSPY%2FRozena.B) for scanner (avira) in md5 table9/39 (23,08%) ADSPY/Rozena.B
Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...  up No previous evidence recordedSaved evidence (1609816 Bytes) of last contact as txt August 26 2010 04:42:04 CEST. aliveSaved log of last contact as txt September 02 2010 20:02:52 CEST. SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(ip) in same window 58.253.235.84 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS17816) in networks tablefollow up this itemfollow up this AS (AS17816) as RSS-Feed AS17816 SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(review) in same window 58.253.235.84 Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ... follow up this domain(downxia.net) downxia.net follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@chinaunicom.cn) as RSS-Feed abuse@chinaunicom.cn follow up this itemfollow up this item 58.248.0.0 - 58.255.255.255 follow up this item UNICOM-GD follow up this item China Unicom Guangdong province networkChina UnicomCNC Group CHINA169 Guangdong Province Network follow up this item ns5.ename.net follow up this item ns2.ename.net follow up this item ns6.ename.net follow up this item ns3.ename.net follow up this item ns4.ename.net Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...
33 645671Report false positive Report closed case make a suggestion 2010-09-02 20:00:49     follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
Saved local log of joebox September 02 2010 20:20:52 CEST.9/38 (23,68%) 
 
ADSPY/Rozena.B
Trojan/Win32.Agent.gen
TrojWare.Win32.TrojanDownloader.Delf.AOQ0
Suspicious:W32/Malware!Gemini
Virus.Downloader.Rozena
TrojanDownloader.Agent.cvwz
Trojan-Downloader.Win32.Agent.ehpd
Artemis!7ED890858813
Suspicious
file 
 lookup in virustotal.com (b32748a959f9caa8512748244052727f)-->[http://www.virustotal.com/file-scan/report.html?id=d8b9a86b8eb1277baa927a252f2e226e5b3690c07700be1e5ec7ba454c766610-1283450720]lookup in threatexpert.comlookup the sha256(d8b9a86b8eb1277baa927a252f2e226e5b3690c07700be1e5ec7ba454c766610) in comodo.comfollow up this md5sum(b32748a959f9caa8512748244052727f)follow up this itemfollow up this virusname (ADSPY%2FRozena.B) as RSS-Feedlookup Virusname at avirafollow up this malware(ADSPY%2FRozena.B) for scanner (avira) in md5 table9/38 (23,68%) ADSPY/Rozena.B
Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...  up No previous evidence recordedSaved evidence (1606144 Bytes) of last contact as txt August 26 2010 04:42:14 CEST. aliveSaved log of last contact as txt September 02 2010 20:02:37 CEST. SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(ip) in same window 58.253.235.84 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS17816) in networks tablefollow up this itemfollow up this AS (AS17816) as RSS-Feed AS17816 SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(review) in same window 58.253.235.84 Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ... follow up this domain(downxia.net) downxia.net follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@chinaunicom.cn) as RSS-Feed abuse@chinaunicom.cn follow up this itemfollow up this item 58.248.0.0 - 58.255.255.255 follow up this item UNICOM-GD follow up this item China Unicom Guangdong province networkChina UnicomCNC Group CHINA169 Guangdong Province Network follow up this item ns5.ename.net follow up this item ns2.ename.net follow up this item ns6.ename.net follow up this item ns3.ename.net follow up this item ns4.ename.net Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...
34 645672Report false positive Report closed case make a suggestion 2010-09-02 20:00:49     follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
Saved local log of joebox September 02 2010 20:17:26 CEST.9/39 (23,08%) 
 
ADSPY/Rozena.B
Trojan/Win32.Agent.gen
TrojWare.Win32.TrojanDownloader.Delf.AOQ0
Suspicious:W32/Malware!Gemini
Virus.Downloader.Rozena
TrojanDownloader.Agent.cvwz
Trojan-Downloader.Win32.Agent.ehpd
Artemis!7ED890858813
Suspicious
file 
 lookup in virustotal.com (997d71ba9cc1ae81dc29eb80e2a08d9f)-->[http://www.virustotal.com/file-scan/report.html?id=1310e7ba185ab3b1f816aee3ef9b7ade0a4b95d3f7eba914e4b47cfbd1f54ab5-1283450752]lookup in threatexpert.comlookup the sha256(1310e7ba185ab3b1f816aee3ef9b7ade0a4b95d3f7eba914e4b47cfbd1f54ab5) in comodo.comfollow up this md5sum(997d71ba9cc1ae81dc29eb80e2a08d9f)follow up this itemfollow up this virusname (ADSPY%2FRozena.B) as RSS-Feedlookup Virusname at avirafollow up this malware(ADSPY%2FRozena.B) for scanner (avira) in md5 table9/39 (23,08%) ADSPY/Rozena.B
Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...  up No previous evidence recordedSaved evidence (1609808 Bytes) of last contact as txt August 26 2010 04:42:24 CEST. aliveSaved log of last contact as txt September 02 2010 20:02:22 CEST. SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(ip) in same window 58.253.235.84 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS17816) in networks tablefollow up this itemfollow up this AS (AS17816) as RSS-Feed AS17816 SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(review) in same window 58.253.235.84 Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ... follow up this domain(downxia.net) downxia.net follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@chinaunicom.cn) as RSS-Feed abuse@chinaunicom.cn follow up this itemfollow up this item 58.248.0.0 - 58.255.255.255 follow up this item UNICOM-GD follow up this item China Unicom Guangdong province networkChina UnicomCNC Group CHINA169 Guangdong Province Network follow up this item ns5.ename.net follow up this item ns2.ename.net follow up this item ns6.ename.net follow up this item ns3.ename.net follow up this item ns4.ename.net Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...
35 645673Report false positive Report closed case make a suggestion 2010-09-02 20:00:49     follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
Saved local log of joebox September 02 2010 20:14:00 CEST.9/39 (23,08%) 
 
ADSPY/Rozena.B
Trojan/Win32.Agent.gen
TrojWare.Win32.TrojanDownloader.Delf.AOQ0
Suspicious:W32/Malware!Gemini
Virus.Downloader.Rozena
TrojanDownloader.Agent.cvwz
Trojan-Downloader.Win32.Agent.ehpd
Artemis!7ED890858813
Suspicious
file 
 lookup in virustotal.com (59105cc2d239e0da2a4b84c7dfca9147)-->[http://www.virustotal.com/file-scan/report.html?id=31437d85c9a6dabe41904a02bed5997c7b50119465c7f59b861ace563d3d6365-1283450641]lookup in threatexpert.comlookup the sha256(31437d85c9a6dabe41904a02bed5997c7b50119465c7f59b861ace563d3d6365) in comodo.comfollow up this md5sum(59105cc2d239e0da2a4b84c7dfca9147)follow up this itemfollow up this virusname (ADSPY%2FRozena.B) as RSS-Feedlookup Virusname at avirafollow up this malware(ADSPY%2FRozena.B) for scanner (avira) in md5 table9/39 (23,08%) ADSPY/Rozena.B
Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...  up No previous evidence recordedSaved evidence (1609832 Bytes) of last contact as txt August 26 2010 04:42:37 CEST. aliveSaved log of last contact as txt September 02 2010 20:02:08 CEST. SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(ip) in same window 58.253.235.84 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS17816) in networks tablefollow up this itemfollow up this AS (AS17816) as RSS-Feed AS17816 SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(review) in same window 58.253.235.84 Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ... follow up this domain(downxia.net) downxia.net follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@chinaunicom.cn) as RSS-Feed abuse@chinaunicom.cn follow up this itemfollow up this item 58.248.0.0 - 58.255.255.255 follow up this item UNICOM-GD follow up this item China Unicom Guangdong province networkChina UnicomCNC Group CHINA169 Guangdong Province Network follow up this item ns5.ename.net follow up this item ns2.ename.net follow up this item ns6.ename.net follow up this item ns3.ename.net follow up this item ns4.ename.net Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...
36 645674Report false positive Report closed case make a suggestion 2010-09-02 20:00:49     follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
Saved local log of joebox September 02 2010 20:09:34 CEST.6/39 (15,38%) 
 
ADSPY/Rozena.B
Suspicious:W32/Malware!Gemini
Virus.Downloader.Rozena
TrojanDownloader.Agent.cvwz
Trojan-Downloader.Win32.Agent.elmr
Suspicious
file 
 lookup in virustotal.com (7c6beccd2ce889773ec27de191aaaaff)-->[http://www.virustotal.com/file-scan/report.html?id=e85c8d2de4878d39c4fa2dabb04855c3405e7d9988db31c4a84db6e00fe10c66-1283450873]lookup in threatexpert.comlookup the sha256(e85c8d2de4878d39c4fa2dabb04855c3405e7d9988db31c4a84db6e00fe10c66) in comodo.comfollow up this md5sum(7c6beccd2ce889773ec27de191aaaaff)follow up this itemfollow up this virusname (ADSPY%2FRozena.B) as RSS-Feedlookup Virusname at avirafollow up this malware(ADSPY%2FRozena.B) for scanner (avira) in md5 table6/39 (15,38%) ADSPY/Rozena.B
Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0902/8/IE ...  up No previous evidence recordedSaved evidence (1583960 Bytes) of last contact as txt September 01 2010 12:32:34 CEST. aliveSaved log of last contact as txt September 02 2010 20:01:54 CEST. SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(ip) in same window 58.253.235.84 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS17816) in networks tablefollow up this itemfollow up this AS (AS17816) as RSS-Feed AS17816 SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(review) in same window 58.253.235.84 Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0902/8/IE ... follow up this domain(downxia.net) downxia.net follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@chinaunicom.cn) as RSS-Feed abuse@chinaunicom.cn follow up this itemfollow up this item 58.248.0.0 - 58.255.255.255 follow up this item UNICOM-GD follow up this item China Unicom Guangdong province networkChina UnicomCNC Group CHINA169 Guangdong Province Network follow up this item ns5.ename.net follow up this item ns2.ename.net follow up this item ns6.ename.net follow up this item ns3.ename.net follow up this item ns4.ename.net Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0902/8/IE ...
37 645646Report false positive Report closed case make a suggestion 2010-09-02 20:00:48     follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
Saved local log of joebox September 02 2010 21:46:44 CEST.8/39 (20,51%) 
 
ADSPY/Rozena.B
Trojan/Win32.Agent.gen
Suspicious:W32/Malware!Gemini
Virus.Downloader.Rozena
TrojanDownloader.Agent.cvwz
Trojan-Downloader.Win32.Agent.ehpd
Artemis!485881C9417C
Suspicious
file 
 lookup in virustotal.com (485881c9417c3a8a388f59fde0fb220c)-->[http://www.virustotal.com/file-scan/report.html?id=f0b26b17061620021e8ed6a198273c6a5f9711ebe124245e333da834dcf71454-1283451049]lookup in threatexpert.comlookup the sha256(f0b26b17061620021e8ed6a198273c6a5f9711ebe124245e333da834dcf71454) in comodo.comfollow up this md5sum(485881c9417c3a8a388f59fde0fb220c)follow up this itemfollow up this virusname (ADSPY%2FRozena.B) as RSS-Feedlookup Virusname at avirafollow up this malware(ADSPY%2FRozena.B) for scanner (avira) in md5 table8/39 (20,51%) ADSPY/Rozena.B
Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...  up No previous evidence recordedSaved evidence (1585248 Bytes) of last contact as txt August 25 2010 09:09:40 CEST. aliveSaved log of last contact as txt September 02 2010 20:09:40 CEST. SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(ip) in same window 58.253.235.84 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS17816) in networks tablefollow up this itemfollow up this AS (AS17816) as RSS-Feed AS17816 SenderBaselookup 58.253.235.84 at Rus CERT university stuttgart germanylookup 58.253.235.84 at apnicfollow up this item(review) in same window 58.253.235.84 Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ... follow up this domain(downxia.net) downxia.net follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@chinaunicom.cn) as RSS-Feed abuse@chinaunicom.cn follow up this itemfollow up this item 58.248.0.0 - 58.255.255.255 follow up this item UNICOM-GD follow up this item China Unicom Guangdong province networkChina UnicomCNC Group CHINA169 Guangdong Province Network follow up this item ns5.ename.net follow up this item ns2.ename.net follow up this item ns6.ename.net follow up this item ns3.ename.net follow up this item ns4.ename.net Safe Virus-Viewer and Analyser may take a minute to complete http://d1.downxia.net/products/0826/8/IE ...
38 645683Report false positive Report closed case make a suggestion 2010-09-02 19:58:11     follow up this itemfollow up this contributor (sub5) as RSS-Feed sub5possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
21/39 (53,85%) 
 
PHP/Backdoor
PHP/Pbot.A
PHP/Pbot.A
PHP:Pbot-A
PHP/BackDoor.Q
Backdoor.PHP.Pbot.A
PHP.Bot
PHP.Shellbot.8
PHP/Phircbot.A
PHP/Pbot.A
Backdoor.PHP.Pbot.A
Backdoor.PHP.Pbot.A
Backdoor.PHP.Pbot
Trojan
Backdoor.PHP.Pbot.g
Backdoor:PHP/Phricbot.A
IRCBot.BCEL
Ma 
 lookup in virustotal.com (1f4e3791717b86fe6a994b6807586b5b)-->[http://www.virustotal.com/file-scan/report.html?id=33b5b033f33a059c281acdde3d622c4164ce1c22c607283ff89ce7b10f50cadf-1283454234]follow up this md5sum(1f4e3791717b86fe6a994b6807586b5b) multiple instances recorded!follow up this itemfollow up this virusname (PHP%2FPbot.A) as RSS-Feedlookup Virusname at avirafollow up this malware(PHP%2FPbot.A) for scanner (avira) in md5 table21/39 (53,85%) PHP/Pbot.A
Safe Virus-Viewer and Analyser may take a minute to complete http://host67.hrwebservices.net/~allstag ...  up No previous evidence recordedSaved evidence (17408 Bytes) of last contact as txt September 02 2010 13:00:22 CEST. aliveSaved log of last contact as txt September 02 2010 21:02:10 CEST. SenderBaselookup 66.147.225.53 at Rus CERT university stuttgart germanylookup 66.147.225.53 at ARINfollow up this item(ip) in same window 66.147.225.53 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS4323) in networks tablefollow up this itemfollow up this AS (AS4323) as RSS-Feed AS4323 SenderBaselookup 66.147.225.53 at Rus CERT university stuttgart germanylookup 66.147.225.53 at ARINfollow up this item(review) in same window 66.147.225.53 Safe Virus-Viewer and Analyser may take a minute to complete http://host67.hrwebservices.net/~allstag ... follow up this domain(hrwebservices.net) hrwebservices.net follow up this itemfollow up this country (US) as RSS-Feed US follow up this itemfollow up this region (ARIN) as RSS-Feed ARIN follow up this itemfollow up this enail (john@hostrocket.com) as RSS-Feed john@hostrocket.com follow up this itemfollow up this item 66.147.224.0 - 66.147.239.255 follow up this item HRWEBSERVICES-2 follow up this item HostRocket Web Services HRWE 21 Corporate Drive - Suite 203 Clifton Park NY 12065 follow up this item dns2.hrnoc.net follow up this item dns1.hrnoc.net follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://host67.hrwebservices.net/~allstag ...
39 645682Report false positive Report closed case make a suggestion 2010-09-02 19:57:08     follow up this itemfollow up this contributor (sub5) as RSS-Feed sub5possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
18/39 (46,15%) 
 
PHP/IRCBOT.AN
PHP/Ircbot.B
PHP:IRCBot-B
PHP.Bot-6
PHP/Pbot.A
PHP/Ircbot.B
PHP:IRCBot-B

Backdoor.PHP.IRCBot
Backdoor
Backdoor.PHP.IRCBot.bu
PHP/BackDoor-EDV
PHP/BackDoor-EDV
PHP/IRCBot.NAD
PHP/Ircbot.BBQX
Bck/IRCBot.CYG
Troj/IRCBot-AFC
Backdoor.PHP.IRCB 
 lookup in virustotal.com (55f7f0c1a795d90f21a0c53d232b63df)-->[http://www.virustotal.com/file-scan/report.html?id=2486a4f3c3e80a196a86a55d37bf8160bfcf5ecebff45aaa8eeed43209bb9593-1283454209]follow up this md5sum(55f7f0c1a795d90f21a0c53d232b63df)follow up this itemfollow up this virusname (PHP%2FIRCBOT.AN) as RSS-Feedlookup Virusname at avirafollow up this malware(PHP%2FIRCBOT.AN) for scanner (avira) in md5 table18/39 (46,15%) PHP/IRCBOT.AN
Safe Virus-Viewer and Analyser may take a minute to complete http://bakso.fileave.com/ping.txt??  up No previous evidence recordedSaved evidence (105486 Bytes) of last contact as txt September 01 2010 06:54:10 CEST. aliveSaved log of last contact as txt September 02 2010 21:02:12 CEST. SenderBaselookup 64.62.181.43 at Rus CERT university stuttgart germanylookup 64.62.181.43 at ARINfollow up this item(ip) in same window 64.62.181.43 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS6939) in networks tablefollow up this itemfollow up this AS (AS6939) as RSS-Feed AS6939 SenderBaselookup 64.62.181.43 at Rus CERT university stuttgart germanylookup 64.62.181.43 at ARINfollow up this item(review) in same window 64.62.181.43 Safe Virus-Viewer and Analyser may take a minute to complete http://bakso.fileave.com/ping.txt?? follow up this domain(fileave.com) fileave.com follow up this itemfollow up this country (US) as RSS-Feed US follow up this itemfollow up this region (ARIN) as RSS-Feed ARIN follow up this itemfollow up this enail (abuse@he.net) as RSS-Feed abuse@he.net follow up this itemfollow up this item 64.62.128.0 - 64.62.255.255 follow up this item HURRICANE-4 follow up this item Hurricane Electric, Inc. HURC 760 Mission Court Fremont CA 94539 follow up this item ns1.ripside.com follow up this item ns2.ripside.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://bakso.fileave.com/ping.txt??
40 645684Report false positive Report closed case make a suggestion 2010-09-02 19:48:15     follow up this itemfollow up this contributor (sub5) as RSS-Feed sub5possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
21/39 (53,85%) 
 
PHP/Limworm.172478
PHP/C99Shell.I
PHP:C99Shell-F
PHP/BackDoor.C99Shell
Backdoor.PHP.ALI
HTM/C99shell.G
PHP.Shell-22
PHP/Shell.B
PHP/C99Shell.I
Backdoor.PHP.ALI
Backdoor.PHP.ALI
Backdoor.PHP.Agent
Backdoor
Backdoor.PHP.C99Shell.cn
Backdoor:PHP/C99shell.F 
 lookup in virustotal.com (684e14c63be2d678f04f4bb871d4d87a)-->[http://www.virustotal.com/file-scan/report.html?id=09bfec942b25e949308e094438368a56eb226b542d59a9a39318c257490b5d89-1283454236]follow up this md5sum(684e14c63be2d678f04f4bb871d4d87a)follow up this itemfollow up this virusname (PHP%2FLimworm.172478) as RSS-Feedlookup Virusname at avirafollow up this malware(PHP%2FLimworm.172478) for scanner (avira) in md5 table21/39 (53,85%) PHP/Limworm.172478
Safe Virus-Viewer and Analyser may take a minute to complete http://getemgirlfriday.com/news//list/me ...  up No previous evidence recordedSaved evidence (172473 Bytes) of last contact as txt August 29 2010 01:45:29 CEST. aliveSaved log of last contact as txt September 02 2010 21:02:08 CEST. SenderBaselookup 75.126.202.88 at Rus CERT university stuttgart germanylookup 75.126.202.88 at ARINfollow up this item(ip) in same window 75.126.202.88 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS36351) in networks tablefollow up this itemfollow up this AS (AS36351) as RSS-Feed AS36351 SenderBaselookup 75.126.202.88 at Rus CERT university stuttgart germanylookup 75.126.202.88 at ARINfollow up this item(review) in same window 75.126.202.88 Safe Virus-Viewer and Analyser may take a minute to complete http://getemgirlfriday.com/news//list/me ... follow up this domain(getemgirlfriday.com) getemgirlfriday.com follow up this itemfollow up this country (US) as RSS-Feed US follow up this itemfollow up this region (ARIN) as RSS-Feed ARIN follow up this itemfollow up this enail (ipadmin@softlayer.com) as RSS-Feed ipadmin@softlayer.com follow up this itemfollow up this item 75.126.0.0 - 75.126.255.255 follow up this item SOFTLAYER-4-3 follow up this item SoftLayer Technologies Inc. SOFTL 1950 N Stemmons Freeway Dallas TX 75207 follow up this item ns101.whbdns.com follow up this item ns100.whbdns.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://getemgirlfriday.com/news//list/me ...
41 645642Report false positive Report closed case make a suggestion 2010-09-02 19:17:31     follow up this itemfollow up this contributor (sub5) as RSS-Feed sub5possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
11/39 (28,21%) 
 
PHP/IRCBOT.E
PHP:IRCBot-I
PHP.IRCBot-4
PHP/Pbot.H
PHP:IRCBot-I

Backdoor.PHP.IRCBot
Backdoor.PHP.IRCBot.e
Heuristic.BehavesLike.JS.BufferOverflow.L
Bck/IRCBot.CYG
PHP_IRCBOT.SMOZ
PHP.ShellBot.N 
 lookup in virustotal.com (6b31e62eeb7e0703bc811df6a1e6b197)-->[http://www.virustotal.com/file-scan/report.html?id=dfff0e5e0064d9fa14901996df6f3069a9b2a57ba63be8affba4536b02eb0de1-1283451460]follow up this md5sum(6b31e62eeb7e0703bc811df6a1e6b197)follow up this itemfollow up this virusname (PHP%2FIRCBOT.E) as RSS-Feedlookup Virusname at avirafollow up this malware(PHP%2FIRCBOT.E) for scanner (avira) in md5 table11/39 (28,21%) PHP/IRCBOT.E
Safe Virus-Viewer and Analyser may take a minute to complete http://dic01.fileave.com/msg.txt???  up No previous evidence recordedSaved evidence (72030 Bytes) of last contact as txt August 31 2010 13:47:17 CEST. aliveSaved log of last contact as txt September 02 2010 20:10:03 CEST. SenderBaselookup 64.62.181.43 at Rus CERT university stuttgart germanylookup 64.62.181.43 at ARINfollow up this item(ip) in same window 64.62.181.43 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS6939) in networks tablefollow up this itemfollow up this AS (AS6939) as RSS-Feed AS6939 SenderBaselookup 64.62.181.43 at Rus CERT university stuttgart germanylookup 64.62.181.43 at ARINfollow up this item(review) in same window 64.62.181.43 Safe Virus-Viewer and Analyser may take a minute to complete http://dic01.fileave.com/msg.txt??? follow up this domain(fileave.com) fileave.com follow up this itemfollow up this country (US) as RSS-Feed US follow up this itemfollow up this region (ARIN) as RSS-Feed ARIN follow up this itemfollow up this enail (abuse@he.net) as RSS-Feed abuse@he.net follow up this itemfollow up this item 64.62.128.0 - 64.62.255.255 follow up this item HURRICANE-4 follow up this item Hurricane Electric, Inc. HURC 760 Mission Court Fremont CA 94539 follow up this item ns2.ripside.com follow up this item ns1.ripside.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://dic01.fileave.com/msg.txt???
42 645641Report false positive Report closed case make a suggestion 2010-09-02 19:00:03     follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
Saved local log of joebox September 02 2010 19:07:48 CEST.15/37 (40,54%) 
 
Trojan/Win32.Zbot
TR/PCK.Katusha.P.18
Gen:Variant.Downloader.10
Trojan.PWS.Panda.485
Gen:Variant.Downloader.10
Gen:Variant.Downloader.10
Trojan.Win32.Spyeye
Packed.Win32.Katusha.p
PWS:Win32/Zbot.gen!Y
a
variant
of
Win32/Kryptik.GKO
Gen:Variant.Downloade 
 lookup in virustotal.com (15dac7d9f71724981b7906787260f790)-->[http://www.virustotal.com/file-scan/report.html?id=bd418e230dd2115885034041e7e5b7a11f9aadd29ab154dbc56569c21698948b-1283446973]lookup in threatexpert.comlookup the sha256(bd418e230dd2115885034041e7e5b7a11f9aadd29ab154dbc56569c21698948b) in comodo.comfollow up this md5sum(15dac7d9f71724981b7906787260f790)follow up this itemfollow up this virusname (TR%2FPCK.Katusha.P.18) as RSS-Feedlookup Virusname at avirafollow up this malware(TR%2FPCK.Katusha.P.18) for scanner (avira) in md5 table15/37 (40,54%) TR/PCK.Katusha.P.18
Safe Virus-Viewer and Analyser may take a minute to complete http://connectionsupport.org/f/bin/uploa ...  up No previous evidence recordedSaved evidence (112640 Bytes) of last contact as txt August 26 2010 10:12:40 CEST. aliveSaved log of last contact as txt September 02 2010 19:01:29 CEST. SenderBaselookup 77.78.240.172 at Rus CERT university stuttgart germanylookup 77.78.240.172 at Ripefollow up this item(ip) in same window 77.78.240.172 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS42560) in networks tablefollow up this itemfollow up this AS (AS42560) as RSS-Feed AS42560 SenderBaselookup 77.78.240.172 at Rus CERT university stuttgart germanylookup 77.78.240.172 at Ripefollow up this item(review) in same window 77.78.240.172 Safe Virus-Viewer and Analyser may take a minute to complete http://connectionsupport.org/f/bin/uploa ... follow up this domain(connectionsupport.org) connectionsupport.org follow up this itemfollow up this country (BA) as RSS-Feed BA follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@globalnet.ba) as RSS-Feed abuse@globalnet.ba follow up this itemfollow up this item 77.78.192.0 - 77.78.255.255 follow up this item BA-GLOBALNET-BH-20070309 follow up this item GLOBALNETGlobalNET Internet Service ProviderBosnia and Herzegovina follow up this item ns2.connectionsupport.org follow up this item ns1.connectionsupport.org follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://connectionsupport.org/f/bin/uploa ...
43 645643Report false positive Report closed case make a suggestion 2010-09-02 18:41:14     follow up this itemfollow up this contributor (sub5) as RSS-Feed sub5possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
25/39 (64,1%) 
 
PHP/Pbot.A
PHP/Pbot.A
PHP:Pbot-A
PHP/BackDoor.K
Trojan.Dropper.RYF
PHP.Bot
PHP/Pbot.D
PHP/Pbot.A
Trojan.Dropper.RYF
Trojan.Dropper.RYF
Backdoor.PHP.Pbot
Backdoor
Backdoor.PHP.Pbot.a
PHP/Malma
PHP/Malma
Backdoor:PHP/Hiebot.B
PHP/Pbot.D
Trojan.Dropper.RYF 
 lookup in virustotal.com (55a6e3ca8acdadc67feddee38df5e741)-->[http://www.virustotal.com/file-scan/report.html?id=5ed364d5638da0c73e48ee17f2c76276a1f2926b4a39366d7dbd5ea9b881bfa3-1283451458]follow up this md5sum(55a6e3ca8acdadc67feddee38df5e741)follow up this itemfollow up this virusname (PHP%2FPbot.A) as RSS-Feedlookup Virusname at avirafollow up this malware(PHP%2FPbot.A) for scanner (avira) in md5 table25/39 (64,1%) PHP/Pbot.A
Safe Virus-Viewer and Analyser may take a minute to complete http://colegiolucilagodoy.cl/lg/munyuk/c ...  up No previous evidence recordedSaved evidence (22343 Bytes) of last contact as txt September 01 2010 00:22:37 CEST. aliveSaved log of last contact as txt September 02 2010 20:09:57 CEST. SenderBaselookup 201.238.235.201 at Rus CERT university stuttgart germanylookup 201.238.235.201 at LACNICfollow up this item(ip) in same window 201.238.235.201 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS14259) in networks tablefollow up this itemfollow up this AS (AS14259) as RSS-Feed AS14259 SenderBaselookup 201.238.235.201 at Rus CERT university stuttgart germanylookup 201.238.235.201 at LACNICfollow up this item(review) in same window 201.238.235.201 Safe Virus-Viewer and Analyser may take a minute to complete http://colegiolucilagodoy.cl/lg/munyuk/c ... follow up this domain(colegiolucilagodoy.cl) colegiolucilagodoy.cl follow up this itemfollow up this country (CL) as RSS-Feed CL follow up this itemfollow up this region (LACNIC) as RSS-Feed LACNIC follow up this itemfollow up this enail (jolea@gtdinternet.com) as RSS-Feed jolea@gtdinternet.com follow up this itemfollow up this item 201.238.224.0 - 201.238.255.255 follow up this item CL-GISA-LACNIC follow up this item Gtd Internet S.A.Moneda, 920, Piso 116500712 - Santiago - RMMoneda, 920, Piso 116500712 - Santiago - RM follow up this item ns2.wirenetchile.com follow up this item ns1.wirenetchile.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://colegiolucilagodoy.cl/lg/munyuk/c ...
44 645624Report false positive Report closed case make a suggestion 2010-09-02 18:40:03     follow up this itemfollow up this contributor (sub13) as RSS-Feed sub13possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
Saved local log of joebox September 02 2010 19:51:20 CEST.16/39 (41,03%) 
 
W32/Renos.A!Generic
Trojan.Generic.KD.32604
Trojan.Siggen.64492
Win32/Renos.D!generic
W32/Renos.A!Generic
Suspicious:W32/Malware!Gemini
Trojan.Generic.KD.32604
Virus
Heuristic.BehavesLike.Win32.Trojan.H
TrojanDownloader:Win32/Renos.MJ
Win32/TrojanDownlo 
 lookup in virustotal.com (b3046ca24d7ea1d8825c40c0638e72a9)-->[http://www.virustotal.com/file-scan/report.html?id=6189517908b5bfbb9dbef20abe8d817d4081bb2eab4f51b84877cb2e499e5a9f-1283447019]lookup in threatexpert.comlookup the sha256(6189517908b5bfbb9dbef20abe8d817d4081bb2eab4f51b84877cb2e499e5a9f) in comodo.comfollow up this md5sum(b3046ca24d7ea1d8825c40c0638e72a9)follow up this itemfollow up this virusname (W32%2FRenos.A%21Generic) as RSS-Feedfollow up this malware(W32%2FRenos.A%21Generic) for scanner (Authentium) in md5 table16/39 (41,03%) W32/Renos.A!Generic
Safe Virus-Viewer and Analyser may take a minute to complete http://bestcodeinfo.com/install.0.exe  up No previous evidence recordedSaved evidence (111104 Bytes) of last contact as txt September 02 2010 19:02:37 CEST. aliveSaved log of last contact as txt September 02 2010 19:02:37 CEST. SenderBaselookup 64.120.169.103 at Rus CERT university stuttgart germanylookup 64.120.169.103 at ARINfollow up this item(ip) in same window 64.120.169.103 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS21788) in networks tablefollow up this itemfollow up this AS (AS21788) as RSS-Feed AS21788 SenderBaselookup 64.120.169.103 at Rus CERT university stuttgart germanylookup 64.120.169.103 at ARINfollow up this item(review) in same window 64.120.169.103 Safe Virus-Viewer and Analyser may take a minute to complete http://bestcodeinfo.com/install.0.exe follow up this domain(bestcodeinfo.com) bestcodeinfo.com follow up this itemfollow up this country (US) as RSS-Feed US follow up this itemfollow up this region (ARIN) as RSS-Feed ARIN follow up this itemfollow up this enail (abuse@hostnoc.net) as RSS-Feed abuse@hostnoc.net follow up this itemfollow up this item 64.120.128.0 - 64.120.191.255 follow up this item HOSTNOC-5BLK follow up this item Network Operations Center Inc. NOC PO Box 591 Scranton PA 18501-0591 follow up this item di3.nserver.ru follow up this item di1.nserver.ru follow up this item di2.nserver.ru follow up this item di4.nserver.ru follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://bestcodeinfo.com/install.0.exe
45 645625Report false positive Report closed case make a suggestion 2010-09-02 18:40:03     follow up this itemfollow up this contributor (sub13) as RSS-Feed sub13possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
Saved local log of joebox September 02 2010 19:46:44 CEST.15/39 (38,46%) 
 
W32/Renos.A!Generic
Trojan.Generic.KD.32604
Trojan.Siggen.64492
Win32/Renos.D!generic
W32/Renos.A!Generic
Suspicious:W32/Malware!Gemini
Trojan.Generic.KD.32604
Virus
Heuristic.BehavesLike.Win32.Trojan.H
TrojanDownloader:Win32/Renos.MJ
Win32/TrojanDownlo 
 lookup in virustotal.com (80a830be5caed1135ef96b16d6b6d44b)-->[http://www.virustotal.com/file-scan/report.html?id=50df5bd858a356da3b133ae5801440111c35748f4e57078f54a1abd17dd9f401-1283447022]lookup in threatexpert.comlookup the sha256(50df5bd858a356da3b133ae5801440111c35748f4e57078f54a1abd17dd9f401) in comodo.comfollow up this md5sum(80a830be5caed1135ef96b16d6b6d44b)follow up this itemfollow up this virusname (W32%2FRenos.A%21Generic) as RSS-Feedfollow up this malware(W32%2FRenos.A%21Generic) for scanner (Authentium) in md5 table15/39 (38,46%) W32/Renos.A!Generic
Safe Virus-Viewer and Analyser may take a minute to complete http://codenewsworld.com/video-plugin.0. ...  up No previous evidence recordedSaved evidence (111104 Bytes) of last contact as txt September 02 2010 19:02:30 CEST. aliveSaved log of last contact as txt September 02 2010 19:02:30 CEST. SenderBaselookup 64.120.169.103 at Rus CERT university stuttgart germanylookup 64.120.169.103 at ARINfollow up this item(ip) in same window 64.120.169.103 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS21788) in networks tablefollow up this itemfollow up this AS (AS21788) as RSS-Feed AS21788 SenderBaselookup 64.120.169.103 at Rus CERT university stuttgart germanylookup 64.120.169.103 at ARINfollow up this item(review) in same window 64.120.169.103 Safe Virus-Viewer and Analyser may take a minute to complete http://codenewsworld.com/video-plugin.0. ... follow up this domain(codenewsworld.com) codenewsworld.com follow up this itemfollow up this country (US) as RSS-Feed US follow up this itemfollow up this region (ARIN) as RSS-Feed ARIN follow up this itemfollow up this enail (abuse@hostnoc.net) as RSS-Feed abuse@hostnoc.net follow up this itemfollow up this item 64.120.128.0 - 64.120.191.255 follow up this item HOSTNOC-5BLK follow up this item Network Operations Center Inc. NOC PO Box 591 Scranton PA 18501-0591 follow up this item di2.nserver.ru follow up this item di1.nserver.ru follow up this item di4.nserver.ru follow up this item di3.nserver.ru follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://codenewsworld.com/video-plugin.0. ...
46 645626Report false positive Report closed case make a suggestion 2010-09-02 18:40:03     follow up this itemfollow up this contributor (sub13) as RSS-Feed sub13possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
Saved local log of joebox September 02 2010 19:43:48 CEST.12/38 (31,58%) 
 
Malware/Win32.Yimfoca
GenPack:Generic.Malware.SYdCprn.93DC05FE
GenPack:Generic.Malware.SYdCprn.93DC05FE
GenPack:Generic.Malware.SYdCprn.93DC05FE
Artemis!2821300BF295
Artemis!2821300BF295
GenPack:Generic.Malware.SYdCprn.93DC05FE
Suspicious
file
Malware.Y 
 lookup in virustotal.com (2821300bf2957cc894bd5296dcf810d2)-->[http://www.virustotal.com/file-scan/report.html?id=7aec9e60fbc277d554aacd88a6484620bab65a8f3cb3ae57c3070fd380fd03c0-1283447034]lookup in threatexpert.comlookup the sha256(7aec9e60fbc277d554aacd88a6484620bab65a8f3cb3ae57c3070fd380fd03c0) in comodo.comfollow up this md5sum(2821300bf2957cc894bd5296dcf810d2)follow up this itemfollow up this virusname (GenPack%3AGeneric.Malware.SYdCprn.93DC05FE) as RSS-Feedfollow up this malware(GenPack%3AGeneric.Malware.SYdCprn.93DC05FE) for scanner (BitDefender) in md5 table12/38 (31,58%) GenPack:Generic.Malware.SYdCprn.93DC05FE
Safe Virus-Viewer and Analyser may take a minute to complete http://photospace-view.com/photo.php  up No previous evidence recordedSaved evidence (63488 Bytes) of last contact as txt September 02 2010 19:02:22 CEST. aliveSaved log of last contact as txt September 02 2010 19:02:22 CEST. SenderBaselookup 67.195.140.219 at Rus CERT university stuttgart germanylookup 67.195.140.219 at ARINfollow up this item(ip) in same window 67.195.140.219 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS36647) in networks tablefollow up this itemfollow up this AS (AS36647) as RSS-Feed AS36647 SenderBaselookup 67.195.140.218 at Rus CERT university stuttgart germanylookup 67.195.140.218 at ARINfollow up this item(review) in same window 67.195.140.218 Safe Virus-Viewer and Analyser may take a minute to complete http://photospace-view.com/photo.php follow up this domain(photospace-view.com) photospace-view.com follow up this itemfollow up this country (US) as RSS-Feed US follow up this itemfollow up this region (ARIN) as RSS-Feed ARIN follow up this itemfollow up this enail (network-abuse@cc.yahoo-inc.com) as RSS-Feed network-abuse@cc.yahoo-inc.com follow up this itemfollow up this item 67.195.0.0 - 67.195.255.255 follow up this item A-YAHOO-US8 follow up this item Yahoo! Inc. YHOO 701 First Ave Sunnyvale CA 94089 follow up this item yns2.yahoo.com follow up this item yns1.yahoo.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://photospace-view.com/photo.php
47 645627Report false positive Report closed case make a suggestion 2010-09-02 18:40:03     follow up this itemfollow up this contributor (sub13) as RSS-Feed sub13possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
Saved local log of joebox September 02 2010 19:30:54 CEST.28/38 (73,68%) 
 
Downloader/Win32.Genome
TR/Dldr.Delphi.Gen
Trojan/Win32.Genome.gen
Win32:Dropper-gen
Downloader.Generic10.LYY
Trojan.Generic.4575304
TrojWare.Win32.Trojan.Agent.Gen
Trojan.DownLoad2.15240
Trojan.Generic.4575304
W32/Genome.AYSB!tr.dldr
Trojan.Generic.457 
 lookup in virustotal.com (b0a63522b139b218a3256a802a0d7c59)-->[http://www.virustotal.com/file-scan/report.html?id=a742f07ce97f9607d8b8964a4464d8f88c2bc5d25a5cbb8545798b0e95321ec2-1283447032]lookup in threatexpert.comlookup the sha256(a742f07ce97f9607d8b8964a4464d8f88c2bc5d25a5cbb8545798b0e95321ec2) in comodo.comfollow up this md5sum(b0a63522b139b218a3256a802a0d7c59)follow up this itemfollow up this virusname (TR%2FDldr.Delphi.Gen) as RSS-Feedlookup Virusname at avirafollow up this malware(TR%2FDldr.Delphi.Gen) for scanner (avira) in md5 table28/38 (73,68%) TR/Dldr.Delphi.Gen
Safe Virus-Viewer and Analyser may take a minute to complete http://lmwoool.com/down/xiaochongzi.exe  up No previous evidence recordedSaved evidence (36352 Bytes) of last contact as txt August 23 2010 07:28:01 CEST. aliveSaved log of last contact as txt September 02 2010 19:02:18 CEST. SenderBaselookup 121.12.115.135 at Rus CERT university stuttgart germanylookup 121.12.115.135 at apnicfollow up this item(ip) in same window 121.12.115.135 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS4134) in networks tablefollow up this itemfollow up this AS (AS4134) as RSS-Feed AS4134 SenderBaselookup 121.12.115.135 at Rus CERT university stuttgart germanylookup 121.12.115.135 at apnicfollow up this item(review) in same window 121.12.115.135 Safe Virus-Viewer and Analyser may take a minute to complete http://lmwoool.com/down/xiaochongzi.exe follow up this domain(lmwoool.com) lmwoool.com follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@gddc.com.cn) as RSS-Feed abuse@gddc.com.cn follow up this itemfollow up this item 121.8.0.0 - 121.15.255.255 follow up this item CHINANET-GD follow up this item CHINANET Guangdong province networkChina TelecomNo.31,jingrong streetBeijing 100032From Guangdong Network of ChinaTelecom follow up this item dns4.4cun.com follow up this item dns3.4cun.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://lmwoool.com/down/xiaochongzi.exe
48 645628Report false positive Report closed case make a suggestion 2010-09-02 18:40:03     follow up this itemfollow up this contributor (sub13) as RSS-Feed sub13possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
Saved local log of joebox September 02 2010 19:28:02 CEST.16/39 (41,03%) 
 
Trojan/Win32.Zbot
TR/PSW.Zbot.113152.Y.2
Agent2.BHUU
Gen:Variant.Bredo.17
Trojan.PWS.Panda.485
Gen:Variant.Bredo.17
Gen:Variant.Bredo.17
PWS.Win32
Generic.dx!tqq
Artemis!4DE5435D5CFD
PWS:Win32/Zbot.gen!Y
a
variant
of
Win32/Kryptik.GJI
Gen:Variant.Bredo. 
 lookup in virustotal.com (4de5435d5cfd354051177d146a182992)-->[http://www.virustotal.com/file-scan/report.html?id=4134beb3feb7518453d614446383f9ae9297b602a79715bd9d14c307dbb64edd-1283447037]lookup in threatexpert.comlookup the sha256(4134beb3feb7518453d614446383f9ae9297b602a79715bd9d14c307dbb64edd) in comodo.comfollow up this md5sum(4de5435d5cfd354051177d146a182992)follow up this itemfollow up this virusname (TR%2FPSW.Zbot.113152.Y.2) as RSS-Feedlookup Virusname at avirafollow up this malware(TR%2FPSW.Zbot.113152.Y.2) for scanner (avira) in md5 table16/39 (41,03%) TR/PSW.Zbot.113152.Y.2
Safe Virus-Viewer and Analyser may take a minute to complete http://connectionsupport.org/f/bin/uploa ...  up No previous evidence recordedSaved evidence (113152 Bytes) of last contact as txt August 27 2010 09:19:23 CEST. aliveSaved log of last contact as txt September 02 2010 19:02:12 CEST. SenderBaselookup 77.78.240.172 at Rus CERT university stuttgart germanylookup 77.78.240.172 at Ripefollow up this item(ip) in same window 77.78.240.172 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS42560) in networks tablefollow up this itemfollow up this AS (AS42560) as RSS-Feed AS42560 SenderBaselookup 77.78.240.172 at Rus CERT university stuttgart germanylookup 77.78.240.172 at Ripefollow up this item(review) in same window 77.78.240.172 Safe Virus-Viewer and Analyser may take a minute to complete http://connectionsupport.org/f/bin/uploa ... follow up this domain(connectionsupport.org) connectionsupport.org follow up this itemfollow up this country (BA) as RSS-Feed BA follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@globalnet.ba) as RSS-Feed abuse@globalnet.ba follow up this itemfollow up this item 77.78.192.0 - 77.78.255.255 follow up this item BA-GLOBALNET-BH-20070309 follow up this item GLOBALNETGlobalNET Internet Service ProviderBosnia and Herzegovina follow up this item ns1.connectionsupport.org follow up this item ns2.connectionsupport.org follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://connectionsupport.org/f/bin/uploa ...
49 645629Report false positive Report closed case make a suggestion 2010-09-02 18:40:03     follow up this itemfollow up this contributor (sub13) as RSS-Feed sub13possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
Saved local log of joebox September 02 2010 19:23:40 CEST.9/38 (23,68%) 
 
TR/Downloader.Gen2
unknown
virus
Win32/DH.AA54534F48
Generic.dx!tqp
Heuristic.BehavesLike.Win32.Downloader.C
probably
unknown
NewHeur_PE
Sus/Spy-B
BehavesLike.Win32.Malware.sfm
(mx-v)
PAK_Generic.001
suspected
of
Unknown.Win32Virus 
 lookup in virustotal.com (f1e42d521c91d745a1b3472ed31d2516)-->[http://www.virustotal.com/file-scan/report.html?id=7287f1ea2eb0b7830e7e61f8764a22e90a404356ae633e218e8e884abf2b9372-1283447033]lookup in threatexpert.comlookup the sha256(7287f1ea2eb0b7830e7e61f8764a22e90a404356ae633e218e8e884abf2b9372) in comodo.comfollow up this md5sum(f1e42d521c91d745a1b3472ed31d2516)follow up this itemfollow up this virusname (TR%2FDownloader.Gen2) as RSS-Feedlookup Virusname at avirafollow up this malware(TR%2FDownloader.Gen2) for scanner (avira) in md5 table9/38 (23,68%) TR/Downloader.Gen2
Safe Virus-Viewer and Analyser may take a minute to complete http://ipv6to.info/kolo7/load/ltjmqu.exe ...  up No previous evidence recordedSaved evidence (20992 Bytes) of last contact as txt September 02 2010 15:14:22 CEST. aliveSaved log of last contact as txt September 02 2010 19:02:09 CEST. SenderBaselookup 193.107.208.71 at Rus CERT university stuttgart germanylookup 193.107.208.71 at Ripefollow up this item(ip) in same window 193.107.208.71 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS21098) in networks tablefollow up this itemfollow up this AS (AS21098) as RSS-Feed AS21098 SenderBaselookup 193.107.208.71 at Rus CERT university stuttgart germanylookup 193.107.208.71 at Ripefollow up this item(review) in same window 193.107.208.71 Safe Virus-Viewer and Analyser may take a minute to complete http://ipv6to.info/kolo7/load/ltjmqu.exe ... follow up this domain(ipv6to.info) ipv6to.info follow up this itemfollow up this country (UA) as RSS-Feed UA follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@mhost.kiev.ua) as RSS-Feed abuse@mhost.kiev.ua follow up this itemfollow up this item 193.107.208.0 - 193.107.211.255 follow up this item SAFESERVICE2-NET follow up this item SAFE SERVICE XXI (MHOST IDC)abuse toMhost Data Center follow up this item ns2.1dns.name follow up this item ns4.1dns.name follow up this item ns1.1dns.name follow up this item ns3.1dns.name follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://ipv6to.info/kolo7/load/ltjmqu.exe ...
50 645623Report false positive Report closed case make a suggestion 2010-09-02 18:40:02     follow up this itemfollow up this contributor (sub13) as RSS-Feed sub13possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
Saved local log of joebox September 02 2010 19:59:20 CEST.14/39 (35,9%) 
 
TR/Agent.axm
Trojan.Generic.KD.32448
Trojan.PWS.Panda.387
Trojan.Generic.KD.32448
Trojan.Generic.KD.32448
Trojan-Spy.Win32.SpyEyes.zd
PWS-Zbot.gen.bp
Artemis!CB7A28A8B783
Win32/Spy.Zbot.ZR
Trojan.Generic.KD.32448
Suspicious
file
High
Risk
Fraudulent
Sec 
 lookup in virustotal.com (cb7a28a8b783d165f607b0b4db6b5a6e)-->[http://www.virustotal.com/file-scan/report.html?id=72a641cf13637024fd49bededf2ac45a7f7ff318f3ce434b379e9a33e8a8641b-1283447033]lookup in threatexpert.comlookup the sha256(72a641cf13637024fd49bededf2ac45a7f7ff318f3ce434b379e9a33e8a8641b) in comodo.comfollow up this md5sum(cb7a28a8b783d165f607b0b4db6b5a6e)follow up this itemfollow up this virusname (TR%2FAgent.axm) as RSS-Feedlookup Virusname at avirafollow up this malware(TR%2FAgent.axm) for scanner (avira) in md5 table14/39 (35,9%) TR/Agent.axm
Safe Virus-Viewer and Analyser may take a minute to complete http://theit.cc/vorox/yettiownssomelilz. ...  up No previous evidence recordedSaved evidence (115712 Bytes) of last contact as txt September 02 2010 19:02:51 CEST. aliveSaved log of last contact as txt September 02 2010 19:02:51 CEST. SenderBaselookup 194.79.250.42 at Rus CERT university stuttgart germanylookup 194.79.250.42 at Ripefollow up this item(ip) in same window 194.79.250.42 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS48876) in networks tablefollow up this itemfollow up this AS (AS48876) as RSS-Feed AS48876 SenderBaselookup 194.79.250.42 at Rus CERT university stuttgart germanylookup 194.79.250.42 at Ripefollow up this item(review) in same window 194.79.250.42 Safe Virus-Viewer and Analyser may take a minute to complete http://theit.cc/vorox/yettiownssomelilz. ... follow up this domain(theit.cc) theit.cc follow up this itemfollow up this country (RU) as RSS-Feed RU follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (nuller@uwnet.ru) as RSS-Feed nuller@uwnet.ru follow up this itemfollow up this item 194.79.250.0 - 194.79.251.255 follow up this item INTERA-NET follow up this item Zhek-Universal LtdINTERA NET follow up this item ns1.rjevski.com follow up this item ns2.kalipso19.cc follow up this item ns3.mamacholi.net follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://theit.cc/vorox/yettiownssomelilz. ...
Click here for other vital incidents