PUA.Win32.IDMan.B
Windows
Tipo de malware
Potentially Unwanted Application
Destructivo?
No
Cifrado
In the Wild:
Sí
Resumen y descripción
It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Detalles técnicos
Detalles de entrada
It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Instalación
Crea las carpetas siguientes:
- %User Profile%\Downloads\Programs
- %User Profile%\Downloads\Compressed
- %All Users Profile%\IDM
- %User Profile%\Downloads\Documents
- %User Profile%\Downloads\Music
- %Application Data%\IDM
- %User Profile%\Downloads\Video
- %Application Data%\DMCache
(Nota: %User Profile% es la carpeta de perfil del usuario activo, que en el caso de Windows 98 y ME suele estar en C:\Windows\Profiles\{nombre de usuario}, en el caso de Windows NT en C:\WINNT\Profiles\{nombre de usuario}, en el caso de Windows 2000(32-bit), XP y Server 2003(32-bit) en C:\Documents and Settings\{nombre de usuario} y en el caso de Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) y 10(64-bit) en C:\Users\{nombre de usuario}).
. %Application Data% es la carpeta Application Data del usuario activo, que en el caso de Windows 98 y ME suele estar ubicada en C:\Windows\Profiles\{nombre de usuario}\Application Data, en el caso de Windows NT en C:\WINNT\Profiles\{nombre de usuario}\Application Data, en el caso de Windows 2000(32-bit), XP y Server 2003(32-bit) en C:\Documents and Settings\{nombre de usuario}\Local Settings\Application Data y en el caso de Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) y 10(64-bit) en C:\Users\{nombre de usuario}\AppData\Roaming.).)Técnica de inicio automático
Se registra como BHO para garantizar su ejecución automática cada vez que se utilice Internet Explorer mediante la introducción de las siguientes claves de registro:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Explorer\
Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}
Otras modificaciones del sistema
Agrega las siguientes entradas de registro:
HKEY_CURRENT_USER\Software\DownloadManager\
IDMBI\IEXPLORE
name = "Internet Explorer"
HKEY_CURRENT_USER\Software\DownloadManager\
IDMBI\IEXPLORE
int = "1"
HKEY_CURRENT_USER\Software\DownloadManager\
IDMBI\Firefox
name = "Mozilla firefox"
HKEY_CURRENT_USER\Software\DownloadManager\
IDMBI\Firefox
int = "1"
HKEY_CURRENT_USER\Software\DownloadManager\
IDMBI\chrome
name = "Google Chrome"
HKEY_CURRENT_USER\Software\DownloadManager\
IDMBI\chrome
int = "1"
HKEY_CURRENT_USER\Software\DownloadManager\
IDMBI\OPERA
name = "Opera"
HKEY_CURRENT_USER\Software\DownloadManager\
IDMBI\OPERA
int = "1"
HKEY_CURRENT_USER\Software\DownloadManager\
IDMBI\Safari
name = "Apple Safari"
HKEY_CURRENT_USER\Software\DownloadManager\
IDMBI\Safari
int = "1"
HKEY_CURRENT_USER\Software\DownloadManager\
SpecialKeys
UseKeyToPrevent = "1"
HKEY_CURRENT_USER\Software\DownloadManager\
SpecialKeys
UseKeyToForce = "0"
HKEY_CURRENT_USER\Software\DownloadManager\
SpecialKeys
AltP = "1"
HKEY_CURRENT_USER\Software\DownloadManager\
SpecialKeys
ShiftP = "0"
HKEY_CURRENT_USER\Software\DownloadManager\
SpecialKeys
CtrlP = "0"
HKEY_CURRENT_USER\Software\DownloadManager\
SpecialKeys
DelP = "0"
HKEY_CURRENT_USER\Software\DownloadManager\
SpecialKeys
AltF = "0"
HKEY_CURRENT_USER\Software\DownloadManager\
SpecialKeys
CtrlF = "0"
HKEY_CURRENT_USER\Software\DownloadManager\
SpecialKeys
ShiftF = "0"
HKEY_CURRENT_USER\Software\DownloadManager\
SpecialKeys
InsF = "1"
HKEY_CURRENT_USER\Software\DownloadManager\
SpecialKeys
CheckMouse = "0"
HKEY_CURRENT_USER\Software\DownloadManager\
SpecialKeys
SkipHtml = "1"
HKEY_CURRENT_USER\Software\DownloadManager
AppDataIDMFolder = "%Application Data%\IDM"
HKEY_CURRENT_USER\Software\DownloadManager
CommonAppDataIDMFolder = "%All Users Profile%\IDM"
HKEY_CURRENT_USER\Software\DownloadManager\
menuExt
ffdownl1_str = "Download with IDM"
HKEY_CURRENT_USER\Software\DownloadManager\
menuExt
ffdownlAll_str = "Download all links with IDM"
HKEY_CURRENT_USER\Software\DownloadManager\
menuExt
ffdownlFLV_str = "Download last requested FLV video"
HKEY_CURRENT_USER\Software\DownloadManager\
menuExt
ffdownl10FLV_str = "Choose from 10 last requested FLV videos"
HKEY_CURRENT_USER\Software\DownloadManager\
menuExt
ffdownlppFLV_str = "Download FLV video with IDM"
HKEY_CURRENT_USER\Software\DownloadManager\
menuExt
ffdownlFLVa_str = "Download last requested FLV video with IDM"
HKEY_CURRENT_USER\Software\DownloadManager\
menuExt
ffdownl10FLVa_str = "Download FLV videos with IDM from 10 last requested"
HKEY_CURRENT_USER\Software\DownloadManager
ExceptionServers = "{random characters}"
HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Compressed
ID = "7"
HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Compressed
mask = "zip rar r0* r1* arj gz sit sitx sea ace bz2 7z"
HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Compressed
pathW = ""
HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Compressed
rememberLastPath = "0"
HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Compressed
forSiteOnly = "0"
HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Compressed
sites = ""
HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Documents
ID = "5"
HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Documents
mask = "doc pdf ppt pps docx pptx"
HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Documents
pathW = ""
HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Documents
rememberLastPath = "0"
HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Documents
forSiteOnly = "0"
HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Documents
sites = ""
HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Music
ID = "2"
HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Music
mask = "mp3 wav wma mpa ram ra aac aif m4a"
HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Music
pathW = ""
HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Music
rememberLastPath = "0"
HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Music
forSiteOnly = "0"
HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Music
sites = ""
HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Programs
ID = "1"
HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Programs
mask = "exe msi"
HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Programs
pathW = ""
HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Programs
rememberLastPath = "0"
HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Programs
forSiteOnly = "0"
HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Programs
sites = ""
HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Video
ID = "3"
HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Video
mask = "avi mpg mpe mpeg asf wmv mov qt rm mp4 flv m4v webm ogv ogg mkv"
HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Video
pathW = ""
HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Video
rememberLastPath = "0"
HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Video
forSiteOnly = "0"
HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Video
sites = ""
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
IDMan.CIDMLinkTransmitter\CLSID
(Default) = "{AC746233-E9D3-49CD-862F-068F7B7CCCA4}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{AC746233-E9D3-49CD-862F-068F7B7CCCA4}
(Default) = "IDMan.CIDMLinkTransmitter"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{AC746233-E9D3-49CD-862F-068F7B7CCCA4}
AppID = "{AC746233-E9D3-49CD-862F-068F7B7CCCA4}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{AC746233-E9D3-49CD-862F-068F7B7CCCA4}\
LocalServer32
(Default) = "{malware file path and name}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{AC746233-E9D3-49CD-862F-068F7B7CCCA4}
(Default) = "IDMan"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{AC746233-E9D3-49CD-862F-068F7B7CCCA4}
RunAs = "Interactive User"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{AC746233-E9D3-49CD-862F-068F7B7CCCA4}
ROTFlags = "1"
HKEY_CURRENT_USER\Software\DownloadManager\
menuExt
iedownl1_str = "Download with IDM"
HKEY_CURRENT_USER\Software\DownloadManager\
menuExt
iedownlAll_str = "Download all links with IDM"
HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer
DownloadUI = "{7D11E719-FF90-479C-B0D7-96EB43EE55D7}"
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Internet Explorer
DownloadUI = "{7D11E719-FF90-479C-B0D7-96EB43EE55D7}"
HKEY_CURRENT_USER\Software\DownloadManager
EnableDriver = "1"
HKEY_CURRENT_USER\Software\DownloadManager
FSPSSettingsChecked = "1"
HKEY_CURRENT_USER\Software\DownloadManager
FSSettingsChecked = "1"
HKEY_CURRENT_USER\Software\DownloadManager
mzcc_ext_vers = "73120"
HKEY_CURRENT_USER\Software\DownloadManager
intAOFRWE = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}
(Default) = "IDM Helper"
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}
NoExplorer = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Explorer\
Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}
(Default) = "IDM Helper"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Explorer\
Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}
NoExplorer = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Google\Chrome\NativeMessagingHosts\
com.tonec.idm
(Default) = "%User Temp%\IDMMsgHost.json"
HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Chrome\NativeMessagingHosts\com.tonec.idm
(Default) = "%User Temp%\IDMMsgHost.json"
HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Chrome\Extensions\ngpampappnmepgilojfohadhhmbhlaek
path = "%User Temp%\IDMGCExt.crx"
HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Chrome\Extensions\ngpampappnmepgilojfohadhhmbhlaek
version = "6.33.5"
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Google\Chrome\Extensions\
ngpampappnmepgilojfohadhhmbhlaek
path = "%User Temp%\IDMGCExt.crx"
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Google\Chrome\Extensions\
ngpampappnmepgilojfohadhhmbhlaek
version = "6.33.5"
Soluciones
Step 1
Los usuarios de Windows ME y XP, antes de llevar a cabo cualquier exploración, deben comprobar que tienen desactivada la opción Restaurar sistema para permitir la exploración completa del equipo.
Step 2
Cierre todas las ventanas abiertas del explorador.
Step 3
Eliminar este valor del Registro
Importante: si modifica el Registro de Windows incorrectamente, podría hacer que el sistema funcione mal de manera irreversible. Lleve a cabo este paso solo si sabe cómo hacerlo o si puede contar con ayuda de su administrador del sistema. De lo contrario, lea este artículo de Microsoft antes de modificar el Registro del equipo.
- In HKEY_CURRENT_USER\Software\DownloadManager\IDMBI\IEXPLORE
- name = "Internet Explorer"
- In HKEY_CURRENT_USER\Software\DownloadManager\IDMBI\IEXPLORE
- int = "1"
- In HKEY_CURRENT_USER\Software\DownloadManager\IDMBI\Firefox
- name = "Mozilla firefox"
- In HKEY_CURRENT_USER\Software\DownloadManager\IDMBI\Firefox
- int = "1"
- In HKEY_CURRENT_USER\Software\DownloadManager\IDMBI\chrome
- name = "Google Chrome"
- In HKEY_CURRENT_USER\Software\DownloadManager\IDMBI\chrome
- int = "1"
- In HKEY_CURRENT_USER\Software\DownloadManager\IDMBI\OPERA
- name = "Opera"
- In HKEY_CURRENT_USER\Software\DownloadManager\IDMBI\OPERA
- int = "1"
- In HKEY_CURRENT_USER\Software\DownloadManager\IDMBI\Safari
- name = "Apple Safari"
- In HKEY_CURRENT_USER\Software\DownloadManager\IDMBI\Safari
- int = "1"
- In HKEY_CURRENT_USER\Software\DownloadManager\SpecialKeys
- UseKeyToPrevent = "1"
- In HKEY_CURRENT_USER\Software\DownloadManager\SpecialKeys
- UseKeyToForce = "0"
- In HKEY_CURRENT_USER\Software\DownloadManager\SpecialKeys
- AltP = "1"
- In HKEY_CURRENT_USER\Software\DownloadManager\SpecialKeys
- ShiftP = "0"
- In HKEY_CURRENT_USER\Software\DownloadManager\SpecialKeys
- CtrlP = "0"
- In HKEY_CURRENT_USER\Software\DownloadManager\SpecialKeys
- DelP = "0"
- In HKEY_CURRENT_USER\Software\DownloadManager\SpecialKeys
- AltF = "0"
- In HKEY_CURRENT_USER\Software\DownloadManager\SpecialKeys
- CtrlF = "0"
- In HKEY_CURRENT_USER\Software\DownloadManager\SpecialKeys
- ShiftF = "0"
- In HKEY_CURRENT_USER\Software\DownloadManager\SpecialKeys
- InsF = "1"
- In HKEY_CURRENT_USER\Software\DownloadManager\SpecialKeys
- CheckMouse = "0"
- In HKEY_CURRENT_USER\Software\DownloadManager\SpecialKeys
- SkipHtml = "1"
- In HKEY_CURRENT_USER\Software\DownloadManager
- AppDataIDMFolder = "%Application Data%\IDM"
- In HKEY_CURRENT_USER\Software\DownloadManager
- CommonAppDataIDMFolder = "%All Users Profile%\IDM"
- In HKEY_CURRENT_USER\Software\DownloadManager\menuExt
- ffdownl1_str = "Download with IDM"
- In HKEY_CURRENT_USER\Software\DownloadManager\menuExt
- ffdownlAll_str = "Download all links with IDM"
- In HKEY_CURRENT_USER\Software\DownloadManager\menuExt
- ffdownlFLV_str = "Download last requested FLV video"
- In HKEY_CURRENT_USER\Software\DownloadManager\menuExt
- ffdownl10FLV_str = "Choose from 10 last requested FLV videos"
- In HKEY_CURRENT_USER\Software\DownloadManager\menuExt
- ffdownlppFLV_str = "Download FLV video with IDM"
- In HKEY_CURRENT_USER\Software\DownloadManager\menuExt
- ffdownlFLVa_str = "Download last requested FLV video with IDM"
- In HKEY_CURRENT_USER\Software\DownloadManager\menuExt
- ffdownl10FLVa_str = "Download FLV videos with IDM from 10 last requested"
- In HKEY_CURRENT_USER\Software\DownloadManager
- ExceptionServers = "{random characters}"
- In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Compressed
- ID = "7"
- In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Compressed
- mask = "zip rar r0* r1* arj gz sit sitx sea ace bz2 7z"
- In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Compressed
- pathW = ""
- In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Compressed
- rememberLastPath = "0"
- In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Compressed
- forSiteOnly = "0"
- In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Compressed
- sites = ""
- In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Documents
- ID = "5"
- In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Documents
- mask = "doc pdf ppt pps docx pptx"
- In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Documents
- pathW = ""
- In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Documents
- rememberLastPath = "0"
- In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Documents
- forSiteOnly = "0"
- In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Documents
- sites = ""
- In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Music
- ID = "2"
- In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Music
- mask = "mp3 wav wma mpa ram ra aac aif m4a"
- In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Music
- pathW = ""
- In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Music
- rememberLastPath = "0"
- In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Music
- forSiteOnly = "0"
- In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Music
- sites = ""
- In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Programs
- ID = "1"
- In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Programs
- mask = "exe msi"
- In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Programs
- pathW = ""
- In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Programs
- rememberLastPath = "0"
- In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Programs
- forSiteOnly = "0"
- In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Programs
- sites = ""
- In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Video
- ID = "3"
- In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Video
- mask = "avi mpg mpe mpeg asf wmv mov qt rm mp4 flv m4v webm ogv ogg mkv"
- In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Video
- pathW = ""
- In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Video
- rememberLastPath = "0"
- In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Video
- forSiteOnly = "0"
- In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Video
- sites = ""
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IDMan.CIDMLinkTransmitter\CLSID
- (Default) = "{AC746233-E9D3-49CD-862F-068F7B7CCCA4}"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{AC746233-E9D3-49CD-862F-068F7B7CCCA4}
- (Default) = "IDMan.CIDMLinkTransmitter"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{AC746233-E9D3-49CD-862F-068F7B7CCCA4}
- AppID = "{AC746233-E9D3-49CD-862F-068F7B7CCCA4}"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{AC746233-E9D3-49CD-862F-068F7B7CCCA4}\LocalServer32
- (Default) = "{malware file path and name}"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AC746233-E9D3-49CD-862F-068F7B7CCCA4}
- (Default) = "IDMan"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AC746233-E9D3-49CD-862F-068F7B7CCCA4}
- RunAs = "Interactive User"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AC746233-E9D3-49CD-862F-068F7B7CCCA4}
- ROTFlags = "1"
- In HKEY_CURRENT_USER\Software\DownloadManager\menuExt
- iedownl1_str = "Download with IDM"
- In HKEY_CURRENT_USER\Software\DownloadManager\menuExt
- iedownlAll_str = "Download all links with IDM"
- In HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer
- DownloadUI = "{7D11E719-FF90-479C-B0D7-96EB43EE55D7}"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer
- DownloadUI = "{7D11E719-FF90-479C-B0D7-96EB43EE55D7}"
- In HKEY_CURRENT_USER\Software\DownloadManager
- EnableDriver = "1"
- In HKEY_CURRENT_USER\Software\DownloadManager
- FSPSSettingsChecked = "1"
- In HKEY_CURRENT_USER\Software\DownloadManager
- FSSettingsChecked = "1"
- In HKEY_CURRENT_USER\Software\DownloadManager
- mzcc_ext_vers = "73120"
- In HKEY_CURRENT_USER\Software\DownloadManager
- intAOFRWE = "1"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}
- (Default) = "IDM Helper"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}
- NoExplorer = "1"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}
- (Default) = "IDM Helper"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}
- NoExplorer = "1"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\NativeMessagingHosts\com.tonec.idm
- (Default) = "%User Temp%\IDMMsgHost.json"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\NativeMessagingHosts\com.tonec.idm
- (Default) = "%User Temp%\IDMMsgHost.json"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\ngpampappnmepgilojfohadhhmbhlaek
- path = "%User Temp%\IDMGCExt.crx"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\ngpampappnmepgilojfohadhhmbhlaek
- version = "6.33.5"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ngpampappnmepgilojfohadhhmbhlaek
- path = "%User Temp%\IDMGCExt.crx"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ngpampappnmepgilojfohadhhmbhlaek
- version = "6.33.5"
Step 4
Buscar y eliminar estas carpetas
- %User Profile%\Downloads\Programs
- %User Profile%\Downloads\Compressed
- %All Users Profile%\IDM
- %User Profile%\Downloads\Documents
- %User Profile%\Downloads\Music
- %Application Data%\IDM
- %User Profile%\Downloads\Video
- %Application Data%\DMCache
Step 5
Explorar el equipo con su producto de Trend Micro para eliminar los archivos detectados como PUA.Win32.IDMan.B En caso de que el producto de Trend Micro ya haya limpiado, eliminado o puesto en cuarentena los archivos detectados, no serán necesarios más pasos. Puede optar simplemente por eliminar los archivos en cuarentena. Consulte esta página de Base de conocimientos para obtener más información.
Rellene nuestra encuesta!