See: https://www.virustotal.com/nl/url/b46b094b15a117f3200c1bebca5302ce408074513ffe716ba8fff23f08ab4581/analysis/1412071526/
https://www.virustotal.com/nl/file/9e0fdae19b145bc8ab8988b652b574dc502d5583f50063b225b16ba65e454443/analysis/1412063550/
htxp://zn.tybests.com/down/zhainan/setup_82_21682_.exe redirects to htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe
htxp://zn.tybests.com/down/zhainan/setup_82_21682_.exe is in Dr.Web malicious sites list!
Checking: htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe
Engine version: 7.0.10.8210
Total virus-finding records: 5467882
File size: 1.33 MB
File MD5: b8a01732c40a79a639c40e01971b5850
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe - archive INNO SETUP
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe/Script0.bin - Ok
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe/Script1.bin - Ok
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe/Script2.bin - archive BINARYREShtxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe/Script2.bin/data001 - Ok
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe/Script2.bin/data002 - Ok
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe/Script2.bin/data003 - Ok
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe/Script2.bin - Ok
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe/0.object - Ok
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe/Embedded_Setup.exe - Ok
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe/{app}\My_Tv.exe - Ok
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe/{tmp}\license.txt - Ok
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe/{app}\SetupTV.dll - Ok
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe/{tmp}\ISSkin.dll - Ok
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe/{tmp}\zhainan.Style - Ok
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe/{win}\biaozhi.ico - Ok
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe/{win}\buy.ico - Ok
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe/{win}\game.ico - Ok
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe/{win}\girl.ico - Ok
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe/{win}\heath.ico - Ok
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe/{win}\ie.ico - Ok
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe/{win}\ie2.ico - Ok
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe/{win}\movie.ico - Ok
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe/{win}\shehu.ico - Ok
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe/{win}\taobao.ico - Ok
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe/{win}\tingxs.ico - Ok
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe/{win}\xiaoyouxi.ico - Ok
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe/{win}\youxi.ico - Ok
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe/{win}\zhibo.ico - Ok
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe/{tmp}\bg1.bmp - Ok
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe/{tmp}\bg2.bmp - Ok
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe/{tmp}\browse1.bmp - Ok
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe/{tmp}\browse2.bmp - Ok
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe/{tmp}\browse3.bmp - Ok
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe/{tmp}\close1.bmp - Ok
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe/{tmp}\close2.bmp - Ok
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe/{tmp}\close3.bmp - Ok
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe/{tmp}\editback.bmp - Ok
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe/{tmp}\Finish1.bmp - Ok
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe/{tmp}\Finish2.bmp - Ok
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe/{tmp}\Finish3.bmp - Ok
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe/{tmp}\Setup1.bmp - Ok
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe/{tmp}\Setup2.bmp - Ok
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe/{tmp}\Setup3.bmp - Ok
htxp://ww.zuowangzhanla.com/down/zhainan/setup_82_21682_.exe - Ok
Scan for: htxp://ww.zuowangzhanla.com/
Hostname: ww.zuowangzhanla.com
IP address: 118.122.37.107
System Details:
Running on: nginx/1.0.15
Outdated Web Server Nginx Found: nginx/1.0.15
index
Severity: Suspicious
Reason: Detected suspicious redirection to external web resources at HTTP level.
Details: Detected HTTP redirection to http://ww.zuowangzhanla.com/ → http://www.nictasoft.com/ace/malware-urls/15553189/ → http://support.clean-mx.com/clean-mx/viruses.php?domain=zuowangzhanla.com&sort=id%20DESC
Multiple threats flagged: http://www.scumware.org/report/A60F16A3D871A3AA8249CE01448E7A40.html
File size[byte]: 0
File type: Unknown
polonus
Page/File MD5: 00000000000000000000000000000000
Scan duration[sec]: 0.001000