PWS:Win32/Fignotok.A (Microsoft); [3.nsis]:W32/Rimecud.gen.u (McAfee); Trojan.ADH (Symantec); ARC:NSIS, [data0003]:Trojan.Win32.VBKrypt.aqr (Kaspersky); Virtool.Win32.Vbinject.Gen.2 (v) (Sunbelt); Trojan.Generic.4564995 (FSecure)

 PLATFORM:

Windows 2000, Windows XP, Windows Server 2003

 OVER ALL RISK RATING:
 DAMAGE POTENTIAL::
 DISTRIBUTION POTENTIAL::
 REPORTED INFECTION:
Low
Medium
High
Critical

  • Threat Type:
    Trojan

  • Destructiveness:
    No

  • Encrypted:
     

  • In the wild::
    Yes

  OVERVIEW

Elimina archivos para impedir la ejecución correcta de programas y aplicaciones.

  TECHNICAL DETAILS

File size: 1,797,131 bytes
File type: EXE
Memory resident: Yes
INITIAL SAMPLES RECEIVED DATE: 06 de марта de 2012

Instalación

Crea las carpetas siguientes:

  • %System Root%\DOCUME~1
  • %System Root%\DOCUME~1\ADMINI~1
  • %User Profile%\LOCALS~1
  • %User Profile%\Application Data\DMCache
  • %User Profile%\Application Data\IDM
  • %User Profile%\My Documents\Downloads
  • %User Profile%\Downloads\Compressed
  • %User Profile%\Downloads\Documents
  • %User Profile%\Downloads\Music
  • %User Profile%\Downloads\Programs
  • %User Profile%\Downloads\Video
  • %User Profile%\IDM\Grabber
  • %User Profile%\Grabber\Projects
  • %User Profile%\IDM\Scheduler

(Nota: %System Root% es la carpeta raíz, normalmente C:\. También es la ubicación del sistema operativo).

. %User Profile% es la carpeta de perfil del usuario activo, que en el caso de Windows 98 y ME suele estar en C:\Windows\Profiles\{nombre de usuario}, en el caso de Windows NT en C:\WINNT\Profiles\{nombre de usuario} y en el caso de Windows 2000, XP y Server 2003 en C:\Documents and Settings\{nombre de usuario}).

)

Técnica de inicio automático

Agrega las siguientes entradas de registro para permitir su ejecución automática cada vez que se inicia el sistema:

HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
IDMan = "%User Temp%\IDMan.exe /onboot"

Se registra como BHO para garantizar su ejecución automática cada vez que se utilice Internet Explorer mediante la introducción de las siguientes claves de registro:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Explorer\
Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}

Otras modificaciones del sistema

Elimina los archivos siguientes:

  • %User Temp%\nsq1.tmp
  • %User Profile%\IDM\temp.htm
  • %Windows%\SoftwareDistribution\DataStore\Logs\edbtmp.log

(Nota: %User Temp% es la carpeta Temp del usuario activo, que en el caso de Windows 2000, XP y Server 2003 suele estar en C:\Documents and Settings\{nombre de usuario}\Local Settings\Temp).

. %User Profile% es la carpeta de perfil del usuario activo, que en el caso de Windows 98 y ME suele estar en C:\Windows\Profiles\{nombre de usuario}, en el caso de Windows NT en C:\WINNT\Profiles\{nombre de usuario} y en el caso de Windows 2000, XP y Server 2003 en C:\Documents and Settings\{nombre de usuario}).

. %Windows% es la carpeta de Windows, que suele estar en C:\Windows o C:\WINNT).

)

Agrega las siguientes entradas de registro como parte de la rutina de instalación:

HKEY_CURRENT_USER\Software\DownloadManager

HKEY_CURRENT_USER\Software\DownloadManager\
MCN

HKEY_CURRENT_USER\Software\DownloadManager\
IDMBI

HKEY_CURRENT_USER\Software\DownloadManager\
IDMBI\IEXPLORE

HKEY_CURRENT_USER\Software\DownloadManager\
IDMBI\Firefox

HKEY_CURRENT_USER\Software\DownloadManager\
IDMBI\OPERA

HKEY_CURRENT_USER\Software\DownloadManager\
IDMBI\chrome

HKEY_CURRENT_USER\Software\DownloadManager\
IDMBI\Safari

HKEY_CURRENT_USER\Software\DownloadManager\
IDMBI\NETSCP

HKEY_CURRENT_USER\Software\DownloadManager\
IDMBI\Mozilla

HKEY_CURRENT_USER\Software\DownloadManager\
SpecialKeys

HKEY_CURRENT_USER\Software\DownloadManager\
menuExt

HKEY_CURRENT_USER\Software\DownloadManager\
Passwords

HKEY_CURRENT_USER\Software\DownloadManager\
ListSettings

HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree

HKEY_CURRENT_USER\Software\DownloadManager\
maxID

HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Compressed

HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Documents

HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Music

HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Programs

HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Video

HKEY_CLASSES_ROOT\IDMan.CIDMLinkTransmitter

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
IDMan.CIDMLinkTransmitter\CLSID

HKEY_CLASSES_ROOT\CLSID\{AC746233-E9D3-49CD-862F-068F7B7CCCA4}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{AC746233-E9D3-49CD-862F-068F7B7CCCA4}\LocalServer32

HKEY_CURRENT_USER\Software\Classes\
CLSID\{07999AC3-058B-40BF-984F-69EB1E554CA7}

HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\MenuExt

HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\MenuExt\Download with IDM

HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\MenuExt\Download all links with IDM

HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\MenuExt\Download FLV video content with IDM

HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\Low Rights

HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\Low Rights\ElevationPolicy

HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\Low Rights\ElevationPolicy\
{E0DACC63-037F-46EE-AC02-E4C7B0FBFEB4}

HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\Low Rights\ElevationPolicy\
{1902485B-CE75-42C1-BA2D-57E660793D9A}

HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\Low Rights\DragDrop

HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\Low Rights\DragDrop\
{19129CDA-AFC0-4330-99BC-C5A834F89006}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
PROTOCOLS\Name-Space Handler\http

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
PROTOCOLS\Name-Space Handler\https

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
PROTOCOLS\Name-Space Handler\ftp

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Explorer\
Browser Helper Objects

HKEY_CURRENT_USER\Software\DownloadManager\
Scheduler

HKEY_CURRENT_USER\Software\DownloadManager\
Queue

Agrega las siguientes entradas de registro:

HKEY_CURRENT_USER\Software\DownloadManager\
IDMBI\IEXPLORE
name = "Internet Explorer"

HKEY_CURRENT_USER\Software\DownloadManager\
IDMBI\IEXPLORE
int = "1"

HKEY_CURRENT_USER\Software\DownloadManager\
IDMBI\Firefox
name = "Mozilla firefox"

HKEY_CURRENT_USER\Software\DownloadManager\
IDMBI\Firefox
int = "1"

HKEY_CURRENT_USER\Software\DownloadManager\
IDMBI\OPERA
name = "Opera"

HKEY_CURRENT_USER\Software\DownloadManager\
IDMBI\OPERA
int = "1"

HKEY_CURRENT_USER\Software\DownloadManager\
IDMBI\chrome
name = "Google Chrome"

HKEY_CURRENT_USER\Software\DownloadManager\
IDMBI\chrome
int = "1"

HKEY_CURRENT_USER\Software\DownloadManager\
IDMBI\Safari
name = "Apple Safari"

HKEY_CURRENT_USER\Software\DownloadManager\
IDMBI\Safari
int = "1"

HKEY_CURRENT_USER\Software\DownloadManager\
IDMBI\NETSCP
name = "Netscape 6 and later"

HKEY_CURRENT_USER\Software\DownloadManager\
IDMBI\NETSCP
int = "1"

HKEY_CURRENT_USER\Software\DownloadManager\
IDMBI\Mozilla
name = "Mozilla"

HKEY_CURRENT_USER\Software\DownloadManager\
IDMBI\Mozilla
int = "1"

HKEY_CURRENT_USER\Software\DownloadManager\
SpecialKeys
UseKeyToPrevent = "1"

HKEY_CURRENT_USER\Software\DownloadManager\
SpecialKeys
UseKeyToForce = "0"

HKEY_CURRENT_USER\Software\DownloadManager\
SpecialKeys
AltP = "1"

HKEY_CURRENT_USER\Software\DownloadManager\
SpecialKeys
ShiftP = "0"

HKEY_CURRENT_USER\Software\DownloadManager\
SpecialKeys
CtrlP = "0"

HKEY_CURRENT_USER\Software\DownloadManager\
SpecialKeys
AltF = "0"

HKEY_CURRENT_USER\Software\DownloadManager\
SpecialKeys
CtrlF = "0"

HKEY_CURRENT_USER\Software\DownloadManager\
SpecialKeys
ShiftF = "0"

HKEY_CURRENT_USER\Software\DownloadManager\
SpecialKeys
InsF = "1"

HKEY_CURRENT_USER\Software\DownloadManager\
SpecialKeys
CheckMouse = "1"

HKEY_CURRENT_USER\Software\DownloadManager
AppDataIDMFolder = "%User Profile%\Application Data\IDM"

HKEY_CURRENT_USER\Software\DownloadManager\
menuExt
ffdownl1_str = "Download with IDM"

HKEY_CURRENT_USER\Software\DownloadManager\
menuExt
ffdownlAll_str = "Download all links with IDM"

HKEY_CURRENT_USER\Software\DownloadManager\
menuExt
ffdownlFLV_str = "Download last requested FLV video"

HKEY_CURRENT_USER\Software\DownloadManager\
menuExt
ffdownl10FLV_str = "Choose from 10 last requested FLV videos"

HKEY_CURRENT_USER\Software\DownloadManager\
menuExt
ffdownlppFLV_str = "Download FLV video with IDM"

HKEY_CURRENT_USER\Software\DownloadManager\
menuExt
ffdownlFLVa_str = "Download last requested FLV video with IDM"

HKEY_CURRENT_USER\Software\DownloadManager\
menuExt
ffdownl10FLVa_str = "Download FLV videos with IDM from 10 last requested"

HKEY_CURRENT_USER\Software\DownloadManager
ExceptionServers = "{random characters}"

HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Compressed
ID = "7"

HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Compressed
mask = "zip rar r0* r1* arj gz sit sitx sea ace bz2 7z"

HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Compressed
pathW = "[REG_NONE, size: 148 bytes]"

HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Compressed
rememberLastPath = "0"

HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Documents
ID = "5"

HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Documents
mask = "doc pdf ppt pps"

HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Documents
pathW = "[REG_NONE, size: 146 bytes]"

HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Documents
rememberLastPath = "0"

HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Music
ID = "2"

HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Music
mask = "mp3 wav wma mpa ram ra aac aif m4a"

HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Music
pathW = "[REG_NONE, size: 138 bytes]"

HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Music
rememberLastPath = "0"

HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Programs
ID = "1"

HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Programs
mask = "exe msi"

HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Programs
pathW = "[REG_NONE, size: 144 bytes]"

HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Programs
rememberLastPath = "0"

HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Video
ID = "3"

HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Video
mask = "avi mpg mpe mpeg asf wmv mov qt rm mp4 flv"

HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Video
pathW = "[REG_NONE, size: 138 bytes]"

HKEY_CURRENT_USER\Software\DownloadManager\
FoldersTree\Video
rememberLastPath = "0"

HKEY_CURRENT_USER\Software\DownloadManager
Extensions = "{random characters}"

HKEY_CURRENT_USER\Software\DownloadManager
LocalPathW = "[REG_NONE, size: 128 bytes]"

HKEY_CURRENT_USER\Software\DownloadManager
TempPath = "%User Profile%\Application Data\IDM"

HKEY_CURRENT_USER\Software\DownloadManager
FindApps = "0"

HKEY_CURRENT_USER\Software\DownloadManager
ExePath = "%User Temp%\IDMan.exe"

HKEY_CURRENT_USER\Software\DownloadManager
idmvers = "v5.18b5 Trial"

HKEY_CURRENT_USER\Software\DownloadManager
LastCheck = "03/04/12"

HKEY_CURRENT_USER\Software\DownloadManager
ConnectionType = "0"

HKEY_CURRENT_USER\Software\DownloadManager
ConnectionSpeed = "0"

HKEY_CURRENT_USER\Software\DownloadManager
LaunchOnStart = "1"

HKEY_CURRENT_USER\Software\DownloadManager
RememberLastSave = "1"

HKEY_CURRENT_USER\Software\DownloadManager
MonitorUrlClipboard = "0"

HKEY_CURRENT_USER\Software\DownloadManager
UseHttpProxy = "0"

HKEY_CURRENT_USER\Software\DownloadManager
UseFtpProxy = "0"

HKEY_CURRENT_USER\Software\DownloadManager
FtpPasive = "0"

HKEY_CURRENT_USER\Software\DownloadManager
IntegrateNN = "1"

HKEY_CURRENT_USER\CLSID\{07999AC3-058B-40BF-984F-69EB1E554CA7}
Model = "4"

HKEY_CURRENT_USER\CLSID\{07999AC3-058B-40BF-984F-69EB1E554CA7}
Therad = "1"

HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\MenuExt\Download with IDM
contexts = "f3"

HKEY_CURRENT_USER\Software\DownloadManager\
menuExt
iedownl1_str = "Download with IDM"

HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\MenuExt\Download all links with IDM
contexts = "f3"

HKEY_CURRENT_USER\Software\DownloadManager\
menuExt
iedownlAll_str = "Download all links with IDM"

HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\MenuExt\Download FLV video content with IDM
contexts = "f3"

HKEY_CURRENT_USER\Software\DownloadManager\
menuExt
iedownlFLV_str = "Download FLV video content with IDM"

HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\Low Rights\ElevationPolicy\
{E0DACC63-037F-46EE-AC02-E4C7B0FBFEB4}
AppName = "IDMan.exe"

HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\Low Rights\ElevationPolicy\
{E0DACC63-037F-46EE-AC02-E4C7B0FBFEB4}
AppPath = "%User Temp%"

HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\Low Rights\ElevationPolicy\
{E0DACC63-037F-46EE-AC02-E4C7B0FBFEB4}
Policy = "3"

HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\Low Rights\ElevationPolicy\
{1902485B-CE75-42C1-BA2D-57E660793D9A}
AppName = "IEMonitor.exe"

HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\Low Rights\ElevationPolicy\
{1902485B-CE75-42C1-BA2D-57E660793D9A}
AppPath = "%User Temp%"

HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\Low Rights\ElevationPolicy\
{1902485B-CE75-42C1-BA2D-57E660793D9A}
Policy = "3"

HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\Low Rights\DragDrop\
{19129CDA-AFC0-4330-99BC-C5A834F89006}
AppName = "IDMan.exe"

HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\Low Rights\DragDrop\
{19129CDA-AFC0-4330-99BC-C5A834F89006}
AppPath = "%User Temp%"

HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\Low Rights\DragDrop\
{19129CDA-AFC0-4330-99BC-C5A834F89006}
Policy = "3"

HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer
DownloadUI = "{7D11E719-FF90-479C-B0D7-96EB43EE55D7}"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Internet Explorer
DownloadUI = "{7D11E719-FF90-479C-B0D7-96EB43EE55D7}"

HKEY_CURRENT_USER\Software\DownloadManager
FSSettingsChecked = "1"

HKEY_CURRENT_USER\Software\DownloadManager
AdvancedIntegration = "0"

HKEY_CURRENT_USER\Software\DownloadManager
mzcc_ext_vers = "25f"

HKEY_CURRENT_USER\Software\DownloadManager
intAOFRWE = "1"

HKEY_CURRENT_USER\Software\DownloadManager
IntegrateMIE = "1"

HKEY_CURRENT_USER\Software\DownloadManager
mzcc_vers = "ca5a"

HKEY_CURRENT_USER\Software\DownloadManager
TrayIcon = "1"

Elimina las siguientes claves de registro:

HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\MenuExt\{random key}

HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\MenuExt\Download with IDMan

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
PROTOCOLS\Name-Space Handler\http\
zzx

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
PROTOCOLS\Name-Space Handler\http\
TDA

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
PROTOCOLS\Name-Space Handler\https\
zzx

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
PROTOCOLS\Name-Space Handler\ftp\
zzx

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
PROTOCOLS\Name-Space Handler\ftp\
TDA

Rutina de infiltración

Infiltra los archivos siguientes:

  • %User Temp%\IDMan.exe
  • %User Temp%\final.exe
  • %User Profile%\Scheduler\s_1.dt
  • %User Profile%\Application Data\chrtmp

(Nota: %User Temp% es la carpeta Temp del usuario activo, que en el caso de Windows 2000, XP y Server 2003 suele estar en C:\Documents and Settings\{nombre de usuario}\Local Settings\Temp).

. %User Profile% es la carpeta de perfil del usuario activo, que en el caso de Windows 98 y ME suele estar en C:\Windows\Profiles\{nombre de usuario}, en el caso de Windows NT en C:\WINNT\Profiles\{nombre de usuario} y en el caso de Windows 2000, XP y Server 2003 en C:\Documents and Settings\{nombre de usuario}).

)

  SOLUTION

Minimum scan engine: 9.200

Step 1

Los usuarios de Windows ME y XP, antes de llevar a cabo cualquier exploración, deben comprobar que tienen desactivada la opción Restaurar sistema para permitir la exploración completa del equipo.

Step 2

Reiniciar en modo seguro

[ learnMore ]

Step 3

Cierre todas las ventanas abiertas del explorador.

Step 4

Eliminar esta clave del Registro

[ learnMore ]

Importante: si modifica el Registro de Windows incorrectamente, podría hacer que el sistema funcione mal de manera irreversible. Lleve a cabo este paso solo si sabe cómo hacerlo o si puede contar con ayuda de su administrador del sistema. De lo contrario, lea este artículo de Microsoft antes de modificar el Registro del equipo.

  • In HKEY_CURRENT_USER\Software
    • DownloadManager
  • In HKEY_CURRENT_USER\Software\DownloadManager
    • MCN
  • In HKEY_CURRENT_USER\Software\DownloadManager
    • IDMBI
  • In HKEY_CURRENT_USER\Software\DownloadManager\IDMBI
    • IEXPLORE
  • In HKEY_CURRENT_USER\Software\DownloadManager\IDMBI
    • Firefox
  • In HKEY_CURRENT_USER\Software\DownloadManager\IDMBI
    • OPERA
  • In HKEY_CURRENT_USER\Software\DownloadManager\IDMBI
    • chrome
  • In HKEY_CURRENT_USER\Software\DownloadManager\IDMBI
    • Safari
  • In HKEY_CURRENT_USER\Software\DownloadManager\IDMBI
    • NETSCP
  • In HKEY_CURRENT_USER\Software\DownloadManager\IDMBI
    • Mozilla
  • In HKEY_CURRENT_USER\Software\DownloadManager
    • SpecialKeys
  • In HKEY_CURRENT_USER\Software\DownloadManager
    • menuExt
  • In HKEY_CURRENT_USER\Software\DownloadManager
    • Passwords
  • In HKEY_CURRENT_USER\Software\DownloadManager
    • ListSettings
  • In HKEY_CURRENT_USER\Software\DownloadManager
    • FoldersTree
  • In HKEY_CURRENT_USER\Software\DownloadManager
    • maxID
  • In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree
    • Compressed
  • In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree
    • Documents
  • In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree
    • Music
  • In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree
    • Programs
  • In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree
    • Video
  • In HKEY_CLASSES_ROOT
    • IDMan.CIDMLinkTransmitter
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IDMan.CIDMLinkTransmitter
    • CLSID
  • In HKEY_CLASSES_ROOT\CLSID
    • {AC746233-E9D3-49CD-862F-068F7B7CCCA4}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AC746233-E9D3-49CD-862F-068F7B7CCCA4}
    • LocalServer32
  • In HKEY_CURRENT_USER\Software\Classes\CLSID
    • {07999AC3-058B-40BF-984F-69EB1E554CA7}
  • In HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer
    • MenuExt
  • In HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt
    • Download with IDM
  • In HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt
    • Download all links with IDM
  • In HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt
    • Download FLV video content with IDM
  • In HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer
    • Low Rights
  • In HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights
    • ElevationPolicy
  • In HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy
    • {E0DACC63-037F-46EE-AC02-E4C7B0FBFEB4}
  • In HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy
    • {1902485B-CE75-42C1-BA2D-57E660793D9A}
  • In HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights
    • DragDrop
  • In HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\DragDrop
    • {19129CDA-AFC0-4330-99BC-C5A834F89006}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Name-Space Handler
    • http
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Name-Space Handler
    • https
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Name-Space Handler
    • ftp
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
    • Browser Helper Objects
  • In HKEY_CURRENT_USER\Software\DownloadManager
    • Scheduler
  • In HKEY_CURRENT_USER\Software\DownloadManager
    • Queue

Step 5

Eliminar este valor del Registro

[ learnMore ]

Importante: si modifica el Registro de Windows incorrectamente, podría hacer que el sistema funcione mal de manera irreversible. Lleve a cabo este paso solo si sabe cómo hacerlo o si puede contar con ayuda de su administrador del sistema. De lo contrario, lea este artículo de Microsoft antes de modificar el Registro del equipo.

  • In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
    • IDMan = "%User Temp%\IDMan.exe /onboot"
  • In HKEY_CURRENT_USER\Software\DownloadManager\IDMBI\IEXPLORE
    • name = "Internet Explorer"
  • In HKEY_CURRENT_USER\Software\DownloadManager\IDMBI\IEXPLORE
    • int = "1"
  • In HKEY_CURRENT_USER\Software\DownloadManager\IDMBI\Firefox
    • name = "Mozilla firefox"
  • In HKEY_CURRENT_USER\Software\DownloadManager\IDMBI\Firefox
    • int = "1"
  • In HKEY_CURRENT_USER\Software\DownloadManager\IDMBI\OPERA
    • name = "Opera"
  • In HKEY_CURRENT_USER\Software\DownloadManager\IDMBI\OPERA
    • int = "1"
  • In HKEY_CURRENT_USER\Software\DownloadManager\IDMBI\chrome
    • name = "Google Chrome"
  • In HKEY_CURRENT_USER\Software\DownloadManager\IDMBI\chrome
    • int = "1"
  • In HKEY_CURRENT_USER\Software\DownloadManager\IDMBI\Safari
    • name = "Apple Safari"
  • In HKEY_CURRENT_USER\Software\DownloadManager\IDMBI\Safari
    • int = "1"
  • In HKEY_CURRENT_USER\Software\DownloadManager\IDMBI\NETSCP
    • name = "Netscape 6 and later"
  • In HKEY_CURRENT_USER\Software\DownloadManager\IDMBI\NETSCP
    • int = "1"
  • In HKEY_CURRENT_USER\Software\DownloadManager\IDMBI\Mozilla
    • name = "Mozilla"
  • In HKEY_CURRENT_USER\Software\DownloadManager\IDMBI\Mozilla
    • int = "1"
  • In HKEY_CURRENT_USER\Software\DownloadManager\SpecialKeys
    • UseKeyToPrevent = "1"
  • In HKEY_CURRENT_USER\Software\DownloadManager\SpecialKeys
    • UseKeyToForce = "0"
  • In HKEY_CURRENT_USER\Software\DownloadManager\SpecialKeys
    • AltP = "1"
  • In HKEY_CURRENT_USER\Software\DownloadManager\SpecialKeys
    • ShiftP = "0"
  • In HKEY_CURRENT_USER\Software\DownloadManager\SpecialKeys
    • CtrlP = "0"
  • In HKEY_CURRENT_USER\Software\DownloadManager\SpecialKeys
    • AltF = "0"
  • In HKEY_CURRENT_USER\Software\DownloadManager\SpecialKeys
    • CtrlF = "0"
  • In HKEY_CURRENT_USER\Software\DownloadManager\SpecialKeys
    • ShiftF = "0"
  • In HKEY_CURRENT_USER\Software\DownloadManager\SpecialKeys
    • InsF = "1"
  • In HKEY_CURRENT_USER\Software\DownloadManager\SpecialKeys
    • CheckMouse = "1"
  • In HKEY_CURRENT_USER\Software\DownloadManager
    • AppDataIDMFolder = "%User Profile%\Application Data\IDM"
  • In HKEY_CURRENT_USER\Software\DownloadManager\menuExt
    • ffdownl1_str = "Download with IDM"
  • In HKEY_CURRENT_USER\Software\DownloadManager\menuExt
    • ffdownlAll_str = "Download all links with IDM"
  • In HKEY_CURRENT_USER\Software\DownloadManager\menuExt
    • ffdownlFLV_str = "Download last requested FLV video"
  • In HKEY_CURRENT_USER\Software\DownloadManager\menuExt
    • ffdownl10FLV_str = "Choose from 10 last requested FLV videos"
  • In HKEY_CURRENT_USER\Software\DownloadManager\menuExt
    • ffdownlppFLV_str = "Download FLV video with IDM"
  • In HKEY_CURRENT_USER\Software\DownloadManager\menuExt
    • ffdownlFLVa_str = "Download last requested FLV video with IDM"
  • In HKEY_CURRENT_USER\Software\DownloadManager\menuExt
    • ffdownl10FLVa_str = "Download FLV videos with IDM from 10 last requested"
  • In HKEY_CURRENT_USER\Software\DownloadManager
    • ExceptionServers = "{random characters}"
  • In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Compressed
    • ID = "7"
  • In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Compressed
    • mask = "zip rar r0* r1* arj gz sit sitx sea ace bz2 7z"
  • In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Compressed
    • pathW = "[REG_NONE, size: 148 bytes]"
  • In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Compressed
    • rememberLastPath = "0"
  • In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Documents
    • ID = "5"
  • In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Documents
    • mask = "doc pdf ppt pps"
  • In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Documents
    • pathW = "[REG_NONE, size: 146 bytes]"
  • In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Documents
    • rememberLastPath = "0"
  • In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Music
    • ID = "2"
  • In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Music
    • mask = "mp3 wav wma mpa ram ra aac aif m4a"
  • In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Music
    • pathW = "[REG_NONE, size: 138 bytes]"
  • In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Music
    • rememberLastPath = "0"
  • In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Programs
    • ID = "1"
  • In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Programs
    • mask = "exe msi"
  • In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Programs
    • pathW = "[REG_NONE, size: 144 bytes]"
  • In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Programs
    • rememberLastPath = "0"
  • In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Video
    • ID = "3"
  • In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Video
    • mask = "avi mpg mpe mpeg asf wmv mov qt rm mp4 flv"
  • In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Video
    • pathW = "[REG_NONE, size: 138 bytes]"
  • In HKEY_CURRENT_USER\Software\DownloadManager\FoldersTree\Video
    • rememberLastPath = "0"
  • In HKEY_CURRENT_USER\Software\DownloadManager
    • Extensions = "{random characters}"
  • In HKEY_CURRENT_USER\Software\DownloadManager
    • LocalPathW = "[REG_NONE, size: 128 bytes]"
  • In HKEY_CURRENT_USER\Software\DownloadManager
    • TempPath = "%User Profile%\Application Data\IDM"
  • In HKEY_CURRENT_USER\Software\DownloadManager
    • FindApps = "0"
  • In HKEY_CURRENT_USER\Software\DownloadManager
    • ExePath = "%User Temp%\IDMan.exe"
  • In HKEY_CURRENT_USER\Software\DownloadManager
    • idmvers = "v5.18b5 Trial"
  • In HKEY_CURRENT_USER\Software\DownloadManager
    • LastCheck = "03/04/12"
  • In HKEY_CURRENT_USER\Software\DownloadManager
    • ConnectionType = "0"
  • In HKEY_CURRENT_USER\Software\DownloadManager
    • ConnectionSpeed = "0"
  • In HKEY_CURRENT_USER\Software\DownloadManager
    • LaunchOnStart = "1"
  • In HKEY_CURRENT_USER\Software\DownloadManager
    • RememberLastSave = "1"
  • In HKEY_CURRENT_USER\Software\DownloadManager
    • MonitorUrlClipboard = "0"
  • In HKEY_CURRENT_USER\Software\DownloadManager
    • UseHttpProxy = "0"
  • In HKEY_CURRENT_USER\Software\DownloadManager
    • UseFtpProxy = "0"
  • In HKEY_CURRENT_USER\Software\DownloadManager
    • FtpPasive = "0"
  • In HKEY_CURRENT_USER\Software\DownloadManager
    • IntegrateNN = "1"
  • In HKEY_CURRENT_USER\CLSID\{07999AC3-058B-40BF-984F-69EB1E554CA7}
    • Model = "4"
  • In HKEY_CURRENT_USER\CLSID\{07999AC3-058B-40BF-984F-69EB1E554CA7}
    • Therad = "1"
  • In HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Download with IDM
    • contexts = "f3"
  • In HKEY_CURRENT_USER\Software\DownloadManager\menuExt
    • iedownl1_str = "Download with IDM"
  • In HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Download all links with IDM
    • contexts = "f3"
  • In HKEY_CURRENT_USER\Software\DownloadManager\menuExt
    • iedownlAll_str = "Download all links with IDM"
  • In HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Download FLV video content with IDM
    • contexts = "f3"
  • In HKEY_CURRENT_USER\Software\DownloadManager\menuExt
    • iedownlFLV_str = "Download FLV video content with IDM"
  • In HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E0DACC63-037F-46EE-AC02-E4C7B0FBFEB4}
    • AppName = "IDMan.exe"
  • In HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E0DACC63-037F-46EE-AC02-E4C7B0FBFEB4}
    • AppPath = "%User Temp%"
  • In HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E0DACC63-037F-46EE-AC02-E4C7B0FBFEB4}
    • Policy = "3"
  • In HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1902485B-CE75-42C1-BA2D-57E660793D9A}
    • AppName = "IEMonitor.exe"
  • In HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1902485B-CE75-42C1-BA2D-57E660793D9A}
    • AppPath = "%User Temp%"
  • In HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1902485B-CE75-42C1-BA2D-57E660793D9A}
    • Policy = "3"
  • In HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\DragDrop\{19129CDA-AFC0-4330-99BC-C5A834F89006}
    • AppName = "IDMan.exe"
  • In HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\DragDrop\{19129CDA-AFC0-4330-99BC-C5A834F89006}
    • AppPath = "%User Temp%"
  • In HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\DragDrop\{19129CDA-AFC0-4330-99BC-C5A834F89006}
    • Policy = "3"
  • In HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer
    • DownloadUI = "{7D11E719-FF90-479C-B0D7-96EB43EE55D7}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer
    • DownloadUI = "{7D11E719-FF90-479C-B0D7-96EB43EE55D7}"
  • In HKEY_CURRENT_USER\Software\DownloadManager
    • FSSettingsChecked = "1"
  • In HKEY_CURRENT_USER\Software\DownloadManager
    • AdvancedIntegration = "0"
  • In HKEY_CURRENT_USER\Software\DownloadManager
    • mzcc_ext_vers = "25f"
  • In HKEY_CURRENT_USER\Software\DownloadManager
    • intAOFRWE = "1"
  • In HKEY_CURRENT_USER\Software\DownloadManager
    • IntegrateMIE = "1"
  • In HKEY_CURRENT_USER\Software\DownloadManager
    • mzcc_vers = "ca5a"
  • In HKEY_CURRENT_USER\Software\DownloadManager
    • TrayIcon = "1"

Step 6

Buscar y eliminar estos archivos

[ learnMore ]
Puede que algunos de los archivos del componente estén ocultos. Asegúrese de que tiene activada la casilla Buscar archivos y carpetas ocultos en la opción "Más opciones avanzadas" para que el resultado de la búsqueda incluya todos los archivos y carpetas ocultos.
  • %User Temp%\IDMan.exe
  • %User Temp%\final.exe
  • %User Profile%\Scheduler\s_1.dt
  • %User Profile%\Application Data\chrtmp

Step 7

Buscar y eliminar estas carpetas

[ learnMore ]
Asegúrese de que tiene activada la casilla Buscar archivos y carpetas ocultos en la opción Más opciones avanzadas para que el resultado de la búsqueda incluya todas las carpetas ocultas.
  • %System Root%\DOCUME~1
  • %System Root%\DOCUME~1\ADMINI~1
  • %User Profile%\LOCALS~1
  • %User Profile%\Application Data\DMCache
  • %User Profile%\Application Data\IDM
  • %User Profile%\My Documents\Downloads
  • %User Profile%\Downloads\Compressed
  • %User Profile%\Downloads\Documents
  • %User Profile%\Downloads\Music
  • %User Profile%\Downloads\Programs
  • %User Profile%\Downloads\Video
  • %User Profile%\IDM\Grabber
  • %User Profile%\Grabber\Projects
  • %User Profile%\IDM\Scheduler

Step 8

Reinicie en modo normal y explore el equipo con su producto de Trend Micro para buscar los archivos identificados como TROJ_VBKRYPT.CD En caso de que el producto de Trend Micro ya haya limpiado, eliminado o puesto en cuarentena los archivos detectados, no serán necesarios más pasos. Puede optar simplemente por eliminar los archivos en cuarentena. Consulte esta página de Base de conocimientos para obtener más información.


Did this description help? Tell us how we did.