Need help? Ask the community or hire an expert.
Go to Avira Answers
Virus:Adware/InstalCor.199
Date discovered:16/02/2012
Type:Adware
In the wild:No
Reported Infections:Low
Distribution Potential:Low
Damage Potential:Low
Static file:Yes
File size:518272 Bytes
MD5 checksum:8e80fc5ad2de1b27ba56b6d183425fd9
VDF version:7.11.23.84 - Thursday, February 16, 2012
IVDF version:7.11.23.84 - Thursday, February 16, 2012

 General Method of propagation:
   • No own spreading routine


Platforms / OS:
   • Windows XP
   • Windows 2003
   • Windows Vista
   • Windows Server 2008
   • Windows 7


Right after execution the following information is displayed:


 Files  It creates the following directories:
   • C:\TEMP\ish1322625\
   • C:\TEMP\is1070216317\



The following files are created:

– Non malicious files:
   • C:\TEMP\ish1322625\defaultOffer\offer_code.txt
   • C:\TEMP\ish1322625\defaultOffer\offer_html.txt
   • %HOME%\Desktop\Continue JDownloader Installation.lnk
   • C:\TEMP\ICReinstall_tr.exe

– Temporary files that might be deleted afterwards:
   • C:\TEMP\00142E81.log
   • C:\TEMP\001430E2.log
   • C:\TEMP\00143111.log
   • %PROGRAM FILES%\is1323187.log
   • C:\TEMP\ish1322625\bootstrap_32718.html
   • C:\TEMP\isf_1323435.flat
   • C:\TEMP\001FB4F1.log
   • C:\TEMP\001FBB98.log

 Miscellaneous Accesses internet resources:
   • cdneu.jdownloadercdn.com
   • cdnus.jdownloadercdn.com

Description inserted by Wensin Lee on Monday, February 20, 2012
Description updated by Wensin Lee on Monday, February 20, 2012

Back . . . .