IDM.exe

IDM Updater

Ymir Entertainment Co., Ltd

The executable IDM.exe has been detected as malware by 13 anti-virus scanners.
Publisher:
Ymir Entertainment Co., Ltd  (signed and verified)

Product:
IDM Updater

Version:
2.238.4.571

MD5:
3f93c919e527e62d7d40c53749b16a62

SHA-1:
c18bfa3bf09d9c640a5c719e0d87a2f46682f93d

SHA-256:
94bf7ec05818858af5d1615b4e117c0229ab4c23d41bcb4da544166f43f01c8e

Scanner detections:
13 / 68

Status:
Malware

Analysis date:
4/26/2024 1:24:47 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.11584824
913

AVG
Trojan horse MSIL4.AGSQ
2014.0.3986

Baidu Antivirus
Trojan.MSIL.Clicker
4.0.3.1486

Bitdefender
Trojan.Generic.11584824
1.0.20.1090

Emsisoft Anti-Malware
Trojan.Generic.11584824
8.14.08.06.03

ESET NOD32
MSIL/TrojanClicker.Agent.NFB trojan
7.0.302.0

F-Secure
Trojan.Generic.11584824
11.2014-06-08_4

G Data
Trojan.Generic.11584824
14.8.24

Kaspersky
Trojan-Clicker.MSIL.Agent
15.0.0.494

MicroWorld eScan
Trojan.Generic.11584824
15.0.0.654

nProtect
Trojan.Generic.11584824
14.08.05.01

Panda Antivirus
Trj/CI.A
14.08.06.03

Sophos
Mal/Generic-S
4.98

File size:
23.6 KB (24,176 bytes)

Product version:
2.238.4.571

Copyright:
Copyright © lalaker1

Original file name:
IDM.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\idm.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
6/6/2012 3:00:00 AM

Valid to:
8/6/2014 2:59:59 AM

Subject:
CN="Ymir Entertainment Co., Ltd", O="Ymir Entertainment Co., Ltd", L=GyangNam-Gu, S=Seoul, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
40DB0889DC1AE4DCB8A753D60220CAB8

File PE Metadata
Compilation timestamp:
7/25/2014 2:12:29 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
384:JP0b3INLtCfl3zh8jlBjSDuq108mO4j58agwD2zCh1nPBy49pMCguuQ3:NWctemlkDk1zHgQth1nP849qzQ3

Entry address:
0x61BE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 02, 00, 10, 00, 00, 00, 20, 00, 00, 80, 18, 00, 00, 00, 38, 00, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 01, 00, 00, 00, 50, 00, 00, 80, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.7950

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
16.5 KB (16,896 bytes)

Remove IDM.exe - Powered by Reason Core Security