idman622.exe

Internet Download Manager

RICH MEDIA SYSTEMS INC.

The application idman622.exe by RICH MEDIA SYSTEMS INC has been detected as a potentially unwanted program by 14 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The installer uses the OpenCandy monitzation platform which will donwload and install offers in the setup for potentially unwanted software including ad/search-supported toolbars. The file has been seen being downloaded from internet-download.ar.1800download.com and multiple other hosts.
Publisher:
RICH MEDIA SYSTEMS INC.  (signed and verified)

Product:
Internet Download Manager

Version:
1.0.0.0

MD5:
a0f6ba72cc97d6d53059ee3ab56a9374

SHA-1:
25f5fe6a8ce6437f1d0a0f69d1ff1033a578ba96

SHA-256:
3725ac8928589800f65fafb32022dc0abdd1f9c90a6e1277b9cb9014642bff35

Scanner detections:
14 / 68

Status:
Potentially unwanted

Explanation:
Packages the OpenCandy software bundler that offers to install additional software and may include web browser add-ons and toolbars which display advertising (based on publisher settings and geo context).

Analysis date:
10/13/2025 4:51:39 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Malware-gen
2014.9-150319

AVG
OpenCandy
2016.0.3166

ESET NOD32
Win32/OpenCandy.C potentially unsafe (variant)
9.11319

G Data
Win32.Adware.OpenCandy
15.3.25

K7 AntiVirus
Trojan
13.200.15262

Malwarebytes
PUP.Optional.OpenCandy
v2015.03.19.07

McAfee
Artemis!A0F6BA72CC97
5600.6822

Qihoo 360 Security
HEUR/QVM42.0.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.Installer.RICHMEDIASYSTEMS
15.5.8.23

Trend Micro House Call
Suspici.F4CBE3E4
7.2.78

VIPRE Antivirus
Sevas-S Installer
38414

File size:
418 KB (428,080 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\idman622.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
2/17/2015 1:00:00 AM

Valid to:
2/18/2016 12:59:59 AM

Subject:
CN=RICH MEDIA SYSTEMS INC., O=RICH MEDIA SYSTEMS INC., L=HENDERSON, S=Nevada, C=US

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
3F87144C25AF8BCF29F29C5A1FEEF4BA

File PE Metadata
Compilation timestamp:
5/20/2013 1:53:00 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:Tiu/MpNSqBh7tD/TYzwzA+QlQ5BHt7Wgu6ptHzAOLQk892w:9/MpN5ltDrYczsQL8F0hcOEl97

Entry address:
0x331C

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 30, 92, 40, 00, 89, 6C, 24, 14, FF, 15, 34, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, BC, 70, 40, 00, 55, FF, 15, AC, 72, 40, 00, 6A, 08, A3, 98, 92, 42, 00, E8, A8, 2E, 00, 00, A3, E4, 91, 42, 00, 55, 8D, 44, 24, 34, 68, B4, 02, 00, 00, 50, 55, 68, 90, 06, 42, 00, FF, 15, 7C, 71, 40, 00, 68, 7C, 93, 40, 00, 68, E0, 81, 42, 00, E8, 13, 2B, 00, 00, FF, 15, 34, 71, 40, 00, BB, 00, 40, 43, 00, 50, 53, E8, 01, 2B, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
24 KB (24,576 bytes)

The file idman622.exe has been seen being distributed by the following 19 URLs.

http://internet-download.ar.1800download.com/get_azure_file/wUiS4WnYccXGwj 8XPavWwllklY0NSr TEWjPtrRt/1jpTDsqSt4yNEcdB6zerC/NXG20ldbIGjPEeutCup00bIjzsGXFUvIoXunSwXlszi1jf/D IaExTYJs55ziVZIRnehAix 18kq9Dm6AzeLS/9Wzc3zMDUPabkgJFsFMaXlEj5tc43EJxEwjbPvUSwkeI/ghbR2TjXr x NwO1nR5i8d8i8Ni8YioPjSK05y0JSs9Si3AzqZel/lCa0RZYJ/Mz4SX/.../2zFYvP3bGvmwV29DRMHnl

http://internet-download.1800download.com/get_azure_file/wUiS4WnYccXBwj pXP7oQlssmV89fDKlEgqtI87Y9ukx53e5 zYmlJxNP0ykYrj2LTPllEZTcWmJEfugGr02w6trh8yeDR7XpnvqBwX9vnGtiffUrd/Qg2gIq5E6kQMbCCO1AX1/lcEj7HKuBzLHRr5e1pKpYiUMK7M0JQpZbPOjAzhtc43EJREwjafsAC1mcoTy2/.../44JDmzR1hemDP 2AV18vSInnl

http://internet-download.1800download.com/get_azure_file/wUiS4WnYccXAwj 1RrjxCgghkkVxZmbzR1 xcteQv U8/zC24jEwnskFdE3mbLn6N3K7yFxQOSCGGOO1WOxj0bIjzsOXFQuT9y74Hk20sni1mbOI svT0mlNq4cygVBBUn61AX1/kMk7qHKmD3GSA7Zdys3zbmNaOec0LRoRZueiRHE8cs3ENFh72LPvSywkcI6x2 s/HD/.../zRIgoiHInnl

http://internet-download.1800download.com/get_azure_file/wUiS4WnYccXAwj uQbjxCggnkkU3LTPkEhr4coOQp h152L0sC8rlY9RagT1Y/j2PnO20gABcSPQSqDiWuklyPpqxcGXFVXPu3q6UhOzpS/gzKuN8YiMg2gIq5Y6kRMbAGSsSTRzntEr/.../9WzM3zYW5bPas5bBIOMaXlDy4iKZDIJBk82emxAC1mcob4w7RsWnux8VDNlu1vB4C2M8ioZWMKgJ3pSKs2lF4f7oLvjF7wfKE2nS sEY8EutWwAHPsuYOXmCQhZ6RIBo47M212 KL X09zhU 61tlGFSjlAgvwppGnzQwvLDGd7HgfhNPSOHnl

http://mirror2.internetdownloadmanager.com/idman620build2.exe

Remove idman622.exe - Powered by Reason Core Security