VirSCAN.org Scanned Report :
Scanned time : 2011/06/01 08:14:02 (EDT)
Scanner results: 16% Scanner(s) (6/37) found malware!
File Name : IncrediMail_Install.exe
File Size : 525664 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : d785355f276fc063e879c1035c224e40
SHA1 : b28f8b8f98e77f1fb190eb079f2dd880177d5b81
Online report :
http://file.virscan.org/report/096d859bd653e5fa16a36d0cad20563a.html
Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 5.1.0.2 20110601190500 2011-06-01 10.91 Riskware.Downloader.Win32.ImLoader.e!A2
AhnLab V3 2011.05.31.03 2011.05.31 2011-05-31 15.57 -
AntiVir 8.2.5.6 7.11.8.216 2011-06-01 0.30 -
Antiy 2.0.18 20110205.7694535 2011-02-05 0.02 -
Arcavir 2011 201105080215 2011-05-08 0.07 -
Authentium 5.1.1 201106010101 2011-06-01 4.19 -
AVAST! 4.7.4 110601-0 2011-06-01 0.06 -
AVG 8.5.850 271.1.1/3668 2011-05-30 0.36 -
BitDefender 7.90123.7406640 7.37559 2011-05-24 0.00 -
ClamAV 0.96.5 13132 2011-05-31 0.16 -
Comodo 4.0 8910 2011-06-01 1.34 -
CP Secure 1.3.0.5 2011.06.01 2011-06-01 0.11 -
Dr.Web 5.0.2.3300 2011.06.01 2011-06-01 13.78 -
F-Prot 4.4.4.56 20110531 2011-05-31 4.95 -
F-Secure 7.02.73807 2011.06.01.03 2011-06-01 12.48 -
Fortinet 4.2.257 13.288 2011-05-31 0.59 -
GData 22.498/22.134 20110601 2011-06-01 10.84 -
ViRobot 20110601 2011.06.01 2011-06-01 0.39 -
Ikarus T3.1.32.20.0 2011.06.01.78513 2011-06-01 4.70 -
JiangMin 13.0.900 2011.05.30 2011-05-30 2.68 -
Kaspersky 5.5.10 2011.06.01 2011-06-01 0.18 not-a-virus:Downloader.Win32.ImLoader.e
KingSoft 2009.2.5.15 2011.6.1.18 2011-06-01 1.93 -
McAfee 5400.1158 6340 2011-05-08 10.14 -
Microsoft 1.6903 2011.06.01 2011-06-01 5.59 -
NOD32 3.0.21 6165 2011-05-30 0.05 probably a variant of Win32/Agent.DYVNCLY trojan
Norman 6.07.08 6.07.00 2011-05-31 12.01 -
Panda 9.05.01 2011.05.31 2011-05-31 19.75 -
Trend Micro 9.200-1012 8.196.06 2011-06-01 0.05 -
Quick Heal 11.00 2011.06.01 2011-06-01 1.34 Downloader.ImLoader.e (Not a Virus)
Rising 20.0 23.60.01.05 2011-05-31 2.68 -
Sophos 3.19.1 4.65 2011-06-01 5.33 -
Sunbelt 3.9.2493.2 9451 2011-05-31 1.23 -
Symantec 1.3.0.24 20110531.002 2011-05-31 0.10 -
nProtect 20110531.02 3459675 2011-05-31 23.80 -
The Hacker 6.7.0.1 v00176 2011-04-18 0.95 Aplicacion/ImLoader.e (Unwanted)
VBA32 3.12.16.0 20110530.2033 2011-05-30 4.58 Downloader.Win32.ImLoader.e
VirusBuster 5.3.0.4 14.0.59.0/5288748 2011-05-31 0.00 -
All processes killed
========== FILES ==========
File move failed. C:\Documents and Settings\MTaylor\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\jar.class-36ac7ff-7152c3f8.class scheduled to be moved on reboot.
C:\Documents and Settings\MTaylor\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\mndrtdsf.jar-4017acd-44deb267.zip moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 373795 bytes
->Flash cache emptied: 456 bytes
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
->Flash cache emptied: 56504 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
User: Marlu Taylor
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: MTaylor
->Temp folder emptied: 231584 bytes
->Temporary Internet Files folder emptied: 1857381 bytes
->Java cache emptied: 11564905 bytes
->Flash cache emptied: 56996 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: nsmith
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 19569 bytes
%systemroot%\System32 .tmp files removed: 3594257 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 483 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 17.00 mb
OTL by OldTimer - Version 3.2.23.0 log created on 06012011_083721
Files\Folders moved on Reboot...
File\Folder C:\Documents and Settings\MTaylor\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\jar.class-36ac7ff-7152c3f8.class not found!
C:\Documents and Settings\MTaylor\Local Settings\Temporary Internet Files\Content.IE5\XI6LSNK2\index[1].htm moved successfully.
C:\Documents and Settings\MTaylor\Local Settings\Temporary Internet Files\Content.IE5\XI6LSNK2\index[2].htm moved successfully.
C:\Documents and Settings\MTaylor\Local Settings\Temporary Internet Files\Content.IE5\Q58UW4SL\online-scanner[1].htm moved successfully.
C:\Documents and Settings\MTaylor\Local Settings\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.
Registry entries deleted on Reboot...