idman618.exe

Internet Download Manager installer

Tonec Inc.

This is a setup and installation application. The file has been seen being downloaded from aihdownload.adobe.com and multiple other hosts.
Publisher:
Tonec Inc.  (signed and verified)

Product:
Internet Download Manager installer

Version:
6, 18, 2, 1

MD5:
c46918640bfcd626a8b62ac40ef91e4b

SHA-1:
1c7c0abb0b6256283ba06171726c530a7a930317

SHA-256:
6cd0ab60e70c15ebf157a2444aedbe922558094be250fc25a8fbf57490c9e221

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
7/22/2018 9:36:49 PM UTC  (today)

File size:
5.5 MB (5,768,368 bytes)

Product version:
6, 18, 2, 1

Copyright:
© 1999-2013. Tonec, Inc. All rights reserved.

Trademarks:
Internet Download Manager (IDM)

Original file name:
installer.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\idman618.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
5/21/2013 3:00:00 AM

Valid to:
6/20/2016 2:59:59 AM

Subject:
CN=Tonec Inc., OU=Internet Download Manager, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Tonec Inc., L=New York, S=New York, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
034F328F3EFF4FB98F5343811788F78A

File PE Metadata
Compilation timestamp:
10/9/2013 12:31:24 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:fwlqeFjma5p1LSL9csWBf0gB3khRabRFYseqabOaGmbvUjaQxLZSAg9WkIrdn4KC:Ima5p1+L9cs0tBSREVSFyxLZSfWkIrdm

Entry address:
0x4276

Entry point:
55, 8B, EC, 6A, FF, 68, C8, 13, 40, 00, 68, 5E, 42, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, 9C, 10, 40, 00, 59, 83, 0D, AC, 6E, 40, 00, FF, 83, 0D, B0, 6E, 40, 00, FF, FF, 15, A0, 10, 40, 00, 8B, 0D, A8, 6E, 40, 00, 89, 08, FF, 15, A4, 10, 40, 00, 8B, 0D, A4, 6E, 40, 00, 89, 08, A1, A8, 10, 40, 00, 8B, 00, A3, B4, 6E, 40, 00, E8, 10, 01, 00, 00, 39, 1D, 40, 6A, 40, 00, 75, 0C, 68, F2, 43, 40, 00, FF, 15, B0, 10...
 
[+]

Entropy:
7.9977  (probably packed)

Code size:
15 KB (15,360 bytes)

The file idman618.exe has been discovered within the following program.

360Amigo is registry optimizer. 360Amigo System Speedup bundles a branded version of the Conduit Toolbar, designed to deliver search based advertising and results. During installation the user is presented in some cases with the option to install the toolbar (on by default).
www.360amigo.com
53% remove it
 
Powered by Should I Remove It?

The file idman618.exe has been seen being distributed by the following 6 URLs.

http://aihdownload.adobe.com/bin/.../install_reader11_en_mssa_aaa_aih.exe

http://trialversions.net/get/.../9885073374

temp:Inter.Down.Mang.Eghelp.6.19.exe

Scan idman618.exe - Powered by Reason Core Security