Associated Malware Groups
The unsafe files using this name are associated with the malware group:
File Behavior
IDMAN.EXE has been seen to perform the following behavior:
- Enables an In Process Object/Server - Common with DLL Injections
- This Process Deletes Other Processes From Disk
- Executes a Process
- Can communicate with other computer systems using HTTP protocols
- This process creates other processes on disk
- The Process is packed and/or encrypted using a software packing process
- Registers a Dynamic Link Library File
- Adds new menu items in the Internet Explorer Right Click menu
- Adds a Registry Key (RUN) to auto start Programs on system start up
- Makes outbound connections to other computers using NETBIOSOUT protocols
- Communicates with other computers using FTP connections
- Can communicate with other computers using TCP protocols
- Modifies the Systems Winsock LSP which could allow control over all communications of the system
- Enables a COM Object/Server on the Local Machine
- Terminates Processes
- Creates a TCP port which listens and is available for communication initiated by other computers
- Writes to another Process's Virtual Memory (Process Hijacking)
- Creation and Registration of a Browser Helper Object in Internet Explorer
- The process hooks code into all running processes which could allow it to take control of the system or record keyboard input, mouse activity and screen contents
- Automatically changes your firewall settings to allow itself or other programs to communicate over the internet
- Sends email using SMTP protocols
- Adds products to the system registry
- Executes Processes stored in Temporary Folders
- Modifies Windows Initialization And System Settings Used On Start up
- Loads and Executes a System Driver File
IDMAN.EXE has been the subject of the following behavior:
- Executed as a Process
- Terminated as a Process
- Added as a Registry auto start to load Program on Boot up
- Has code inserted into its Virtual Memory space by other programs
- Created as a process on disk
- Deleted as a process from disk
- Enabled as a COM Object/Server on the Local Machine
- Executed from Temporary Folders
Country Of Origin
The filename IDMAN.EXE was first seen on May 15 2007 in the following geographical regions of the Prevx community:
- The United States on May 15 2007
- Canada on May 15 2007
- Europe on May 30 2007
- India on May 30 2007
- Australia on Jun 22 2007
- Saudi Arabia on Oct 14 2007
- Spain on Dec 21 2007
- Iran, Islamic Republic of on Feb 9 2010
File Name Aliases
IDMAN.EXE can also use the following file names:
- IDMAN .EXE
- TMP4.TMP
- TMP40.TMP
- IDM_5.11 PORTABLE/IDM_5.11 PORTABLE/APP/INTERNET DOWNLOAD MANAGER/IDMAN.EXE
- TMP1744.TMP
- TMP454.TMP
- INTERNET DOWNLOAD MANAGER.EXE
- IDM5.12FINAL-CRACK/IDMAN.EXE
- CRACK+KEYGEN/CRACK_REA/IDMAN.EXE
- IDMAN.EXE.BAK
- _IDMAN.EXE
Filesizes
The following file size has been seen:
- 896,768 bytes
- 920,064 bytes
- 800,256 bytes
- 856,576 bytes
- 931,760 bytes
- 3,179,952 bytes
- 844,288 bytes
File Type
The filename IDMAN.EXE refers to many versions of an executable program.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.