• All Community
    • All Community
    • Forums
    • Ideas
    • Blogs
Advanced

Not what you are looking for? Ask the experts!

This forum thread needs a solution.
Kudos0

SONAR.AM.C.P!g12 ?

Hi,When I ran the IDM update to 6.29 build 1, Norton Security blocked the IDM1.tmp file. Norton Security detected this file as SONAR.AM.C.P! g12. Does someone have the same problem? is this a false positive? I sent a Symantec file.My program:NS 22.10.1.10,Windows 10

Replies

Kudos1 Stats

Re: SONAR.AM.C.P!g12 ?

Please tell us what Norton is telling you regarding this event.

For information regarding this event > from Norton pop-up > View Details > Copy to Clipboard &or from Norton history > More Options > Copy to Clipboard > paste here.

For second opinion choose File &/or Search hash at VirusTotal


If you believe Norton made a mistaken detection, you may submit a dispute at. https://submit.symantec.com/false_positive/.


SONAR.AM.C.P!g12
https://www.symantec.com/security_response/writeup.jsp?docid=2016-110102-3138-99

Kudos0

Re: SONAR.AM.C.P!g12 ?

Filename: idm1.tmp
Threat name: SONAR.AM.C.P!g12Full Path: Not Available

____________________________

____________________________


On computers as of
24/06/2017 at 19:07:20

Last Used
24/06/2017 at 19:07:20

Startup Item
Yes

Launched
Yes

SONAR Protection monitors for suspicious program activity on your computer.


____________________________


idm1.tmp Threat name: SONAR.AM.C.P!g12
Locate


Many Users
Tens of thousands of users in the Norton Community have used this file.

Mature
This file was released 4 months ago.

High
This file risk is high.


____________________________


Source: External Media

Source File:
idm1.tmp

____________________________

File Actions

File: c:\users\genge\appdata\local\temp\idm_setup_temp\ idm1.tmp Threat Removed
File: c:\program files (x86)\internet download manager\ downlwithidm.dll Threat Removed
File: c:\program files (x86)\internet download manager\ IDMan.exe Removed
File: c:\program files (x86)\internet download manager\ idmbrbtn.dll Threat Removed
File: c:\program files (x86)\internet download manager\ idmbroker.exe Threat Removed
File: c:\program files (x86)\internet download manager\ idmcchandler7.dll Threat Removed
File: c:\program files (x86)\internet download manager\ idmfsa.dll Threat Removed
File: c:\program files (x86)\internet download manager\ idmftype.dll Threat Removed
File: c:\program files (x86)\internet download manager\ idmgetall.dll Threat Removed
File: c:\program files (x86)\internet download manager\ IDMGrHlp.exe Threat Removed
File: c:\program files (x86)\internet download manager\ IDMIECC.dll Threat Removed
File: c:\program files (x86)\internet download manager\ idmindex.dll Threat Removed
File: c:\program files (x86)\internet download manager\ idmmkb.dll Threat Removed
File: c:\program files (x86)\internet download manager\ idmmzcc7.dll Threat Removed
File: c:\program files (x86)\internet download manager\ idmnetmon.dll Threat Removed
File: c:\program files (x86)\internet download manager\ idmshellext.dll Threat Removed
File: c:\program files (x86)\internet download manager\ idmtdi32.sys Removed
File: c:\program files (x86)\internet download manager\ idmvconv.dll Threat Removed
File: c:\program files (x86)\internet download manager\ idmvs.dll Threat Removed
File: c:\program files (x86)\internet download manager\ idmwfp32.sys Removed
File: c:\program files (x86)\internet download manager\ iemonitor.exe Threat Removed
File: c:\program files (x86)\internet download manager\ mediumilstart.exe Threat Removed
File: c:\program files (x86)\internet download manager\ uninstall.exe Removed
File: c:\program files (x86)\internet download manager\ license.txt Threat Removed
File: c:\program files (x86)\internet download manager\ idman.chm Threat Removed
File: c:\program files (x86)\internet download manager\ idmantypeinfo.tlb Threat Removed
File: c:\program files (x86)\internet download manager\ IEExt.htm Threat Removed
File: c:\program files (x86)\internet download manager\ IEGetAll.htm Threat Removed
File: c:\program files (x86)\internet download manager\languages\ idm_fa.lng Threat Removed
File: c:\program files (x86)\internet download manager\ idmtdi.cat Threat Removed
File: c:\program files (x86)\internet download manager\ tips.txt Threat Removed
File: c:\program files (x86)\internet download manager\ tutor.chm Threat Removed
File: c:\program files (x86)\internet download manager\languages\ idm_ar.lng Threat Removed
File: c:\program files (x86)\internet download manager\languages\ idm_de.lng Threat Removed
File: c:\program files (x86)\internet download manager\languages\ idm_es.lng Threat Removed
File: c:\program files (x86)\internet download manager\languages\ idm_fr.lng Threat Removed
File: c:\program files (x86)\internet download manager\languages\ idm_it.lng Threat Removed
File: c:\program files (x86)\internet download manager\languages\ idm_ptbr.lng Threat Removed
File: c:\program files (x86)\internet download manager\languages\ idm_nl.lng Threat Removed
File: c:\program files (x86)\internet download manager\languages\ template.lng Threat Removed
File: c:\program files (x86)\internet download manager\languages\ tips_ar.txt Threat Removed
File: c:\program files (x86)\internet download manager\languages\ tips_de.txt Threat Removed
File: c:\program files (x86)\internet download manager\languages\ tips_es.txt Threat Removed
File: c:\program files (x86)\internet download manager\languages\ tips_fr.txt Threat Removed
File: c:\program files (x86)\internet download manager\languages\ tips_it.txt Threat Removed
File: c:\program files (x86)\internet download manager\languages\ tips_ptbr.txt Threat Removed
File: c:\program files (x86)\internet download manager\languages\ tips_nl.txt Threat Removed
File: c:\program files (x86)\internet download manager\Toolbar\ 3d_style_3.tbi Threat Removed
File: c:\program files (x86)\internet download manager\Toolbar\ 3d_large_3.bmp Threat Removed
File: c:\program files (x86)\internet download manager\Toolbar\ 3d_largehot_3.bmp Threat Removed
File: c:\program files (x86)\internet download manager\Toolbar\ 3d_small_3.bmp Threat Removed
File: c:\program files (x86)\internet download manager\Toolbar\ 3d_smallhot_3.bmp Threat Removed
File: c:\program files (x86)\internet download manager\ grabber.chm Threat Removed
File: c:\program files (x86)\internet download manager\ idmmzcc.xpi Threat Removed
File: c:\program files (x86)\internet download manager\ scheduler.chm Threat Removed
File: c:\program files (x86)\internet download manager\ IEGetVL.htm Threat Removed
File: c:\program files (x86)\internet download manager\ IEGetVL2.htm Threat Removed
File: c:\program files (x86)\internet download manager\ defexclist.txt Threat Removed
File: c:\program files (x86)\internet download manager\languages\ idm_tr.lng Threat Removed
File: c:\program files (x86)\internet download manager\languages\ tips_tr.txt Threat Removed
File: c:\program files (x86)\internet download manager\ idmwfp.inf Threat Removed
File: c:\program files (x86)\internet download manager\ idmtdi.inf Threat Removed
File: c:\program files (x86)\internet download manager\ idmshellext64.dll Threat Removed
File: c:\program files (x86)\internet download manager\ idmbrbtn64.dll Threat Removed
File: c:\program files (x86)\internet download manager\ idmwfp64.sys Removed
File: c:\program files (x86)\internet download manager\ idmtdi64.sys Removed
File: c:\program files (x86)\internet download manager\ idmwfp.cat Threat Removed
File: c:\program files (x86)\internet download manager\languages\ idm_ru.lng Threat Removed
File: c:\program files (x86)\internet download manager\languages\ tips_ru.txt Threat Removed
File: c:\program files (x86)\internet download manager\languages\ idm_th.lng Threat Removed
File: c:\program files (x86)\internet download manager\languages\ tips_th.txt Threat Removed
File: c:\program files (x86)\internet download manager\languages\ idm_pl.lng Threat Removed
File: c:\program files (x86)\internet download manager\languages\ tips_pl.txt Threat Removed
File: c:\program files (x86)\internet download manager\languages\ tips_fa.txt Threat Removed
File: c:\program files (x86)\internet download manager\ idmiecc64.dll Threat Removed
File: c:\program files (x86)\internet download manager\ idmgetall64.dll Threat Removed
File: c:\program files (x86)\internet download manager\ downlwithidm64.dll Threat Removed
File: c:\program files (x86)\internet download manager\ idmintegrator64.exe Threat Removed
File: c:\program files (x86)\internet download manager\ IDMFType.dat Threat Removed
File: c:\program files (x86)\internet download manager\ idmftype64.dll Threat Removed
File: c:\program files (x86)\internet download manager\ idmnetmon64.dll Removed
File: c:\program files (x86)\internet download manager\languages\ template_inst.lng Threat Removed
File: c:\program files (x86)\internet download manager\languages\ inst_ru.lng Threat Removed
File: c:\program files (x86)\internet download manager\languages\ inst_fr.lng Threat Removed
File: c:\program files (x86)\internet download manager\languages\ inst_src.lng Threat Removed
File: c:\program files (x86)\internet download manager\languages\ inst_ar.lng Threat Removed
File: c:\program files (x86)\internet download manager\languages\ inst_ptbr.lng Threat Removed
File: c:\program files (x86)\internet download manager\languages\ inst_it.lng Threat Removed
File: c:\program files (x86)\internet download manager\languages\ inst_kr.lng Threat Removed
File: c:\program files (x86)\internet download manager\languages\ inst_de.lng Threat Removed
File: c:\program files (x86)\internet download manager\languages\ inst_fa.lng Threat Removed
File: c:\program files (x86)\internet download manager\ IDMGCExt.crx Threat Removed
File: c:\program files (x86)\internet download manager\languages\ inst_chn.lng Threat Removed
File: c:\program files (x86)\internet download manager\languages\ inst_th.lng Threat Removed
File: c:\program files (x86)\internet download manager\languages\ inst_ua.lng Threat Removed
File: c:\program files (x86)\internet download manager\languages\ inst_dk.lng Threat Removed
File: c:\program files (x86)\internet download manager\languages\ inst_id.lng Threat Removed
File: c:\program files (x86)\internet download manager\languages\ inst_cz.lng Threat Removed
File: c:\program files (x86)\internet download manager\languages\ inst_iw.lng Threat Removed
File: c:\program files (x86)\internet download manager\languages\ inst_tr.lng Threat Removed
File: c:\program files (x86)\internet download manager\languages\ inst_sk.lng Threat Removed
File: c:\program files (x86)\internet download manager\languages\ inst_pl.lng Threat Removed
File: c:\program files (x86)\internet download manager\Toolbar\ 3d_large_3_hdpi15.bmp Threat Removed
File: c:\program files (x86)\internet download manager\Toolbar\ 3d_largehot_3_hdpi15.bmp Threat Removed
File: c:\program files (x86)\internet download manager\languages\ inst_cht.lng Threat Removed
File: c:\program files (x86)\internet download manager\languages\ inst_hu.lng Threat Removed
File: c:\program files (x86)\internet download manager\languages\ inst_es.lng Threat Removed
File: c:\program files (x86)\internet download manager\languages\ inst_pt.lng Threat Removed
File: c:\program files (x86)\internet download manager\languages\ inst_bg.lng Threat Removed
File: c:\program files (x86)\internet download manager\languages\ inst_gr.lng Threat Removed
File: c:\program files (x86)\internet download manager\languages\ inst_al.lng Threat Removed
File: c:\program files (x86)\internet download manager\languages\ inst_my.lng Threat Removed
File: c:\program files (x86)\internet download manager\ idmmzcc7_64.dll Threat Removed
File: c:\program files (x86)\internet download manager\ idmcchandler7_64.dll Threat Removed
File: c:\program files (x86)\internet download manager\ idmmzcc2.xpi Threat Removed
File: c:\program files (x86)\internet download manager\languages\ inst_uz.lng Threat Removed
File: c:\program files (x86)\internet download manager\languages\ inst_vn.lng Threat Removed
File: c:\program files (x86)\internet download manager\ idmmzcc3.xpi Threat Removed
File: c:\program files (x86)\internet download manager\ idmsetup2.log Threat Removed
____________________________

Registry Actions

Registry change: HKEY_USERS\S-1-5-21-4178908595-2914001671-1019688389-1001\Software\Microsoft\Windows\CurrentVersion\ Run->IDMan Threat Removed
Registry change: HKEY_CLASSES_ROOT\CLSID\ {0055C089-8582-441B-A0BF-17B458C2A3A8}, Registry Hive: 32 bit Threat Removed
Registry change: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ {0055C089-8582-441B-A0BF-17B458C2A3A8}, Registry Hive: 32 bit Threat Removed
Registry change: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ Session Manager->PendingFileRenameOperations, Registry Hive: 64 bit Threat Removed
Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\ Internet Download Manager->InstallStatus:3, Registry Hive: 64 bit Repaired
Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\ Internet Download Manager->InstallStatus:2, Registry Hive: 64 bit Repaired
Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ Internet Download Manager->Publisher:Tonec Inc., Registry Hive: 64 bit Repaired
Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Internet Download Manager->URLInfoAbout:http:// www . internetdownloadmanager . com, Registry Hive: 64 bit Repaired
Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Internet Download Manager->HelpLink: http :// www . internetdownloadmanager . com/ contact_us.html, Registry Hive: 64 bit Repaired
Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ RunOnce->GrpConv, Registry Hive: 64 bit Threat Removed
Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ Explorer->GlobalAssocChangedCounter:2, Registry Hive: 64 bit Repaired
Registry change: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ Session Manager->PendingFileRenameOperations:..., Registry Hive: 64 bit Repaired
Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\ {E0DACC63-037F-46EE-AC02-E4C7B0FBFEB4}->AppName:IDMan.exe, Registry Hive: 64 bit Repaired
Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E0DACC63-037F-46EE-AC02-E4C7B0FBFEB4}->AppPath:C:\Program Files (x86)\ Internet Download Manager, Registry Hive: 64 bit Repaired
Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\ {E0DACC63-037F-46EE-AC02-E4C7B0FBFEB4}->Policy:3, Registry Hive: 64 bit Repaired
Registry change: HKEY_USERS\S-1-5-21-4178908595-2914001671-1019688389-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\ {1902485B-CE75-42C1-BA2D-57E660793D9A}->AppName:IEMonitor.exe, Registry Hive: 64 bit Repaired
Registry change: HKEY_USERS\S-1-5-21-4178908595-2914001671-1019688389-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1902485B-CE75-42C1-BA2D-57E660793D9A}->AppPath:C:\Program Files (x86)\ Internet Download Manager, Registry Hive: 64 bit Repaired
Registry change: HKEY_USERS\S-1-5-21-4178908595-2914001671-1019688389-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\ {1902485B-CE75-42C1-BA2D-57E660793D9A}->Policy:3, Registry Hive: 64 bit Repaired
Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\DragDrop\ {F6E1B27E-F2DA-4919-9DBD-CAB90A1D662B}->AppName:IDMan.exe, Registry Hive: 64 bit Repaired
Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\DragDrop\{F6E1B27E-F2DA-4919-9DBD-CAB90A1D662B}->AppPath:C:\Program Files (x86)\ Internet Download Manager, Registry Hive: 64 bit Repaired
Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\DragDrop\ {F6E1B27E-F2DA-4919-9DBD-CAB90A1D662B}->Policy:3, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\ {AC746233-E9D3-49CD-862F-068F7B7CCCA4}->AppID:{AC746233-E9D3-49CD-862F-068F7B7CCCA4}, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\AppID\ {AC746233-E9D3-49CD-862F-068F7B7CCCA4}->RunAs:Interactive User, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\AppID\ {AC746233-E9D3-49CD-862F-068F7B7CCCA4}->ROTFlags:1, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}\ ProgID, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}\ Programmable, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}\ TypeLib, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}\ VersionIndependentProgID, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\ {5312C54E-A385-46B7-B200-ABAF81B03935}, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\ {5312C54E-A385-46B7-B200-ABAF81B03935}, Registry Hive: 64 bit Threat Removed
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}\Implemented Categories\ {59FB2056-D625-48D0-A944-1A85B5AB2640}, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}\ Implemented Categories, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}\ ProgID, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}\ Programmable, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}\ TypeLib, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}\ VersionIndependentProgID, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\ {0055C089-8582-441B-A0BF-17B458C2A3A8}, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\ {0055C089-8582-441B-A0BF-17B458C2A3A8}, Registry Hive: 64 bit Threat Removed
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}\ ProgID, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}\ Programmable, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}\ TypeLib, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}\ VersionIndependentProgID, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\ {436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\ {436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}, Registry Hive: 64 bit Threat Removed
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\ Control, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\ Insertable, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\MiscStatus\ 1, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\ MiscStatus, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\ ProgID, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\ Programmable, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\ ToolboxBitmap32, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\ TypeLib, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\ Version, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\ VersionIndependentProgID, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\ {52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\ {52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}, Registry Hive: 64 bit Threat Removed
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{CDD67718-A430-4AB9-A939-83D9074B0038}\ ProgID, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{CDD67718-A430-4AB9-A939-83D9074B0038}\ Programmable, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{CDD67718-A430-4AB9-A939-83D9074B0038}\ TypeLib, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{CDD67718-A430-4AB9-A939-83D9074B0038}\ VersionIndependentProgID, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\ {CDD67718-A430-4AB9-A939-83D9074B0038}, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\ {CDD67718-A430-4AB9-A939-83D9074B0038}, Registry Hive: 64 bit Threat Removed
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{4764030F-2733-45B9-AE62-3D1F4F6F2861}\ ProgID, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{4764030F-2733-45B9-AE62-3D1F4F6F2861}\ Programmable, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{4764030F-2733-45B9-AE62-3D1F4F6F2861}\ TypeLib, Registry Hive: 64 bit Repaired
Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ Explorer->GlobalAssocChangedCounter:4, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\ IDMIECC.IDMHelperLinksStorage.1, Registry Hive: 64 bit Threat Removed
Registry change: HKEY_CLASSES_ROOT\ IDMIECC.IDMHelperLinksStorage, Registry Hive: 64 bit Threat Removed
Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ Explorer->GlobalAssocChangedCounter:8, Registry Hive: 64 bit Repaired
____________________________

Startup Actions

\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}\InprocServer32 (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:7488) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}\InprocServer32:ThreadingModel (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:7488) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}\InprocServer32 (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:7488) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}\InprocServer32:ThreadingModel (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:7488) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}\InprocServer32 (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:7488) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}\InprocServer32:ThreadingModel (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:7488) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\InprocServer32 (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:7488) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\InprocServer32:ThreadingModel (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:7488) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{CDD67718-A430-4AB9-A939-83D9074B0038}\InprocServer32 (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:7488) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{CDD67718-A430-4AB9-A939-83D9074B0038}\InprocServer32:ThreadingModel (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:7488) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{4764030F-2733-45B9-AE62-3D1F4F6F2861}\InprocServer32 (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:7488) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}\InprocServer32 (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:504) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}\InprocServer32:ThreadingModel (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:504) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}\InprocServer32 (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:504) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}\InprocServer32:ThreadingModel (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:504) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\IDMIECC.IDMHelperLinksStorage.1\CLSID (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:504) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\IDMIECC.IDMHelperLinksStorage\CLSID (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:504) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}\InprocServer32 (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:504) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}\InprocServer32:ThreadingModel (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:504) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\InprocServer32 (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:504) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\InprocServer32:ThreadingModel (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:504) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{CDD67718-A430-4AB9-A939-83D9074B0038}\InprocServer32 (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:504) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{CDD67718-A430-4AB9-A939-83D9074B0038}\InprocServer32:ThreadingModel (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:504) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}\InprocServer32 (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:18044) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}\InprocServer32:ThreadingModel (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:18044) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}\InprocServer32 (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:18044) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}\InprocServer32:ThreadingModel (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:18044) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}\InprocServer32 (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:18044) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}\InprocServer32:ThreadingModel (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:18044) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\InprocServer32 (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:18044) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\InprocServer32:ThreadingModel (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:18044) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{CDD67718-A430-4AB9-A939-83D9074B0038}\InprocServer32 (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:18044) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{CDD67718-A430-4AB9-A939-83D9074B0038}\InprocServer32:ThreadingModel (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:18044) No action taken
____________________________

System Settings Actions

Event: Process start (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:7488) No action taken
(Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:7488) No action taken
Event: Process start: c:\Windows\SysWOW64\ net.exe, PID:13044 (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:7488) No action taken
Event: Process start: c:\Windows\System32\ rundll32.exe, PID:1632 (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:7488) No action taken
Event: PE file creation: c:\windows\temp\ old1b0a.tmp (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:7488) No action taken
Event: PE file creation: c:\windows\system32\drivers\ set1b68.tmp (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:7488) No action taken
Event: Process start: c:\Windows\System32\ runonce.exe, PID:2288 (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:7488) No action taken
Event: Process start: c:\Windows\SysWOW64\ net.exe, PID:12320 (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:7488) No action taken
Event: Process start (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:504) No action taken
(Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:504) No action taken
Event: Process start: c:\Windows\SysWOW64\ net.exe, PID:10348 (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:504) No action taken
Event: Process start: c:\Windows\System32\ rundll32.exe, PID:14036 (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:504) No action taken
Event: PE file creation: c:\windows\temp\ old7562.tmp (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:504) No action taken
Event: PE file creation: c:\windows\system32\drivers\ set75a1.tmp (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:504) No action taken
Event: Process start: c:\Windows\System32\ runonce.exe, PID:16016 (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:504) No action taken
Event: Process start: c:\Windows\SysWOW64\ net.exe, PID:16376 (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:504) No action taken
Event: Process start (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:18408) No action taken
(Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:18408) No action taken
(Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:18044) No action taken
Event: Process start: c:\Windows\SysWOW64\ net.exe, PID:15992 (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:18044) No action taken
Event: Process start: c:\Windows\System32\ rundll32.exe, PID:15876 (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:18044) No action taken
Event: PE file creation: c:\windows\temp\ old7b76.tmp (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:18044) No action taken
Event: PE file creation: c:\windows\system32\drivers\ set7ced.tmp (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:18044) No action taken
Event: Process start: c:\Windows\System32\ runonce.exe, PID:17412 (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:18044) No action taken
Event: Process start: c:\Windows\SysWOW64\ net.exe, PID:19608 (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:18044) No action taken
Event: Process start (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:10596) No action taken
(Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:10596) No action taken
Event: Process start: c:\Windows\SysWOW64\ net.exe, PID:10008 (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:10596) No action taken
Event: Process start: c:\Windows\System32\ rundll32.exe, PID:10116 (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:10596) No action taken
Event: PE file creation: c:\windows\temp\ olda38e.tmp (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:10596) No action taken
Event: PE file creation: c:\windows\system32\drivers\ seta468.tmp (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:10596) No action taken
Event: Process start: c:\Windows\System32\ runonce.exe, PID:11212 (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:10596) No action taken
Event: Process start: c:\users\genge\appdata\local\temp\idm_setup_temp\ idm1.tmp, PID:10596 (Performed by c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp, PID:10596) No action taken
____________________________


File Thumbprint - SHA:
Not available
File Thumbprint - MD5:
Not available

Kudos0

Re: SONAR.AM.C.P!g12 ?

hi

me to today  i delete Internet Download Manager for this reason

is IDM have a virus?

Kudos0

Re: SONAR.AM.C.P!g12 ?

Hi there... 

I've already reported this issue. They mentioned me within 72 hours issues will be clear. Because White-listing may take up to 72 hours to take effect via Live Update. 72 hours Since yesterday. 

Kudos0

Re: SONAR.AM.C.P!g12 ?

Hmm, hard to tell from your submission (screenshot).  Your sample looks like idman628.
I pulled IDM, just now, from internetdownloadmanager.com

File: idman629build1.exe
File size: 6.87 MB (7,202,040 bytes)
MD5 checksum: 17EFED5E28E62B4E587E150C446B30F6
SHA256 checksum: 5EAD2E2DCA9C7584C80F794F949A7BFE838FF4431ECC443D4602E6B0EA6A1F5B

maybe, you used mirror or different source or prior sample ?

Kudos0

Re: SONAR.AM.C.P!g12 ?

 I downloaded via the auto-update IDM. And today I downloaded from the official site (not mirror).And when I started the installation IDM 6.29 of the NS once again blocked the program.

Filename: idman.exe
Threat name: SONAR.AM.C.P!g12Full Path: Not Available

____________________________

____________________________


On computers as of
Not Available

Last Used
 at

Startup Item
Yes

Launched
Yes

SONAR Protection monitors for suspicious program activity on your computer.


____________________________


idman.exe Threat name: SONAR.AM.C.P!g12
Locate


Unknown
It is unknown how many users in the Norton Community have used this file.

Unknown
This file release is currently not known.

High
This file risk is high.


____________________________


Source: External Media


____________________________

File Actions

File: c:\program files (x86)\internet download manager\ idman.exe No Action Required
File: c:\users\genge\appdata\roaming\idm\ defextmap.dat Threat Removed
File: c:\users\genge\appdata\roaming\idm\ urlexclist.dat Threat Removed
File: c:\program files (x86)\internet download manager\idmedgeext\ background.js Threat Removed
File: c:\program files (x86)\internet download manager\idmedgeext\ captured.html Threat Removed
File: c:\program files (x86)\internet download manager\idmedgeext\ content.js Threat Removed
File: c:\program files (x86)\internet download manager\idmedgeext\ document.js Threat Removed
File: c:\program files (x86)\internet download manager\idmedgeext\ manifest.json Threat Removed
File: c:\program files (x86)\internet download manager\idmedgeext\ welcome.html Threat Removed
File: c:\program files (x86)\internet download manager\idmedgeext\ welcome.js Threat Removed
File: c:\program files (x86)\internet download manager\idmedgeext\_metadata\ computed_hashes.json Threat Removed
File: c:\program files (x86)\internet download manager\idmedgeext\_metadata\ verified_contents.json Threat Removed
Directory: c:\users\genge\appdata\roaming\idm\dwnldata\genge\ idm_iw_385 No Action Required
Directory: c:\users\genge\appdata\roaming\idm\dwnldata\genge\ tips_he_386 No Action Required
Directory: c:\program files (x86)\internet download manager\ idmedgeext Removed
Directory: c:\users\genge\appdata\roaming\idm\dwnldata\genge\ idm_iw_389 No Action Required
Directory: c:\users\genge\appdata\roaming\idm\dwnldata\genge\ tips_he_390 No Action Required
Directory: c:\program files (x86)\internet download manager\idmedgeext\ images Removed
Directory: c:\program files (x86)\internet download manager\idmedgeext\ _locales Removed
Directory: c:\program files (x86)\internet download manager\idmedgeext\ _metadata Threat Removed
Directory: c:\program files (x86)\internet download manager\idmedgeext\_locales\ ar Removed
Directory: c:\program files (x86)\internet download manager\idmedgeext\_locales\ de Removed
Directory: c:\program files (x86)\internet download manager\idmedgeext\_locales\ en Removed
____________________________

Registry Actions

Registry change: HKEY_USERS\S-1-5-21-4178908595-2914001671-1019688389-1001\Software\DownloadManager\ menuExt->ffdownl1_str:idm הורד באמצעות, Registry Hive: 64 bit Repaired
Registry change: HKEY_USERS\S-1-5-21-4178908595-2914001671-1019688389-1001\Software\DownloadManager\ menuExt->ffdownlAll_str:הורד את כל הלינקים באמצעות IDM, Registry Hive: 64 bit Repaired
Registry change: HKEY_USERS\S-1-5-21-4178908595-2914001671-1019688389-1001\Software\DownloadManager\ menuExt->ffdownlFLV_str:IDM הורד וידיאו האחרון שנתבקש באמצעות (FLV), Registry Hive: 64 bit Repaired
Registry change: HKEY_USERS\S-1-5-21-4178908595-2914001671-1019688389-1001\Software\DownloadManager\ menuExt->ffdownl10FLV_str:FLV בחר מתוך 10 וידאו האחרונים, Registry Hive: 64 bit Repaired
Registry change: HKEY_USERS\S-1-5-21-4178908595-2914001671-1019688389-1001\Software\DownloadManager\ menuExt->ffdownlppFLV_str:IDM הורד וידיאו באמצעות (FLV), Registry Hive: 64 bit Repaired
Registry change: HKEY_USERS\S-1-5-21-4178908595-2914001671-1019688389-1001\Software\DownloadManager\ menuExt->ffdownlFLVa_str:IDM הורד וידיאו האחרון שנתבקש, באמצעות (FLV), Registry Hive: 64 bit Repaired
Registry change: HKEY_USERS\S-1-5-21-4178908595-2914001671-1019688389-1001\Software\DownloadManager\ menuExt->ffdownl10FLVa_str:IDM הורד וידיאו מתוך רשימת 10 האחרונים של (FLV), Registry Hive: 64 bit Repaired
Registry change: HKEY_USERS\S-1-5-21-4178908595-2914001671-1019688389-1001\Software\DownloadManager\ maxID->maxID:384, Registry Hive: 64 bit Repaired
Registry change: HKEY_USERS\S-1-5-21-4178908595-2914001671-1019688389-1001\Software\DownloadManager\385\ ChList, Registry Hive: 64 bit Repaired
Registry change: HKEY_USERS\S-1-5-21-4178908595-2914001671-1019688389-1001\Software\DownloadManager\ 385->Status:5, Registry Hive: 64 bit Repaired
Registry change: HKEY_USERS\S-1-5-21-4178908595-2914001671-1019688389-1001\Software\DownloadManager\ 385, Registry Hive: 64 bit Repaired
Registry change: HKEY_USERS\S-1-5-21-4178908595-2914001671-1019688389-1001\Software\DownloadManager\ menuExt->ffdownl1_str:Download with IDM, Registry Hive: 64 bit Repaired
Registry change: HKEY_USERS\S-1-5-21-4178908595-2914001671-1019688389-1001\Software\DownloadManager\ menuExt->ffdownlAll_str:Download all links with IDM, Registry Hive: 64 bit Repaired
Registry change: HKEY_USERS\S-1-5-21-4178908595-2914001671-1019688389-1001\Software\DownloadManager\ menuExt->ffdownlFLV_str:Download last requested FLV video, Registry Hive: 64 bit Repaired
Registry change: HKEY_USERS\S-1-5-21-4178908595-2914001671-1019688389-1001\Software\DownloadManager\ menuExt->ffdownl10FLV_str:Choose from 10 last requested FLV videos, Registry Hive: 64 bit Repaired
Registry change: HKEY_USERS\S-1-5-21-4178908595-2914001671-1019688389-1001\Software\DownloadManager\ menuExt->ffdownlppFLV_str:Download FLV video with IDM, Registry Hive: 64 bit Repaired
Registry change: HKEY_USERS\S-1-5-21-4178908595-2914001671-1019688389-1001\Software\DownloadManager\ menuExt->ffdownlFLVa_str:Download last requested FLV video with IDM, Registry Hive: 64 bit Repaired
Registry change: HKEY_USERS\S-1-5-21-4178908595-2914001671-1019688389-1001\Software\DownloadManager\ menuExt->ffdownl10FLVa_str:Download FLV videos with IDM from 10 last requested, Registry Hive: 64 bit Repaired
Registry change: HKEY_USERS\S-1-5-21-4178908595-2914001671-1019688389-1001\Software\DownloadManager\ maxID->maxID:385, Registry Hive: 64 bit Repaired
Registry change: HKEY_USERS\S-1-5-21-4178908595-2914001671-1019688389-1001\Software\DownloadManager\386\ ChList, Registry Hive: 64 bit Repaired
Registry change: HKEY_USERS\S-1-5-21-4178908595-2914001671-1019688389-1001\Software\DownloadManager\ 386, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}\ ProgID, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}\ Programmable, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}\ TypeLib, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}\ VersionIndependentProgID, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\ {5312C54E-A385-46B7-B200-ABAF81B03935}, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\ {5312C54E-A385-46B7-B200-ABAF81B03935}, Registry Hive: 64 bit Threat Removed
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}\Implemented Categories\ {59FB2056-D625-48D0-A944-1A85B5AB2640}, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}\ Implemented Categories, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}\ ProgID, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}\ Programmable, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}\ TypeLib, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}\ VersionIndependentProgID, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\ {0055C089-8582-441B-A0BF-17B458C2A3A8}, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\ {0055C089-8582-441B-A0BF-17B458C2A3A8}, Registry Hive: 64 bit Threat Removed
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}\ ProgID, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}\ Programmable, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}\ TypeLib, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}\ VersionIndependentProgID, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\ {436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\ {436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}, Registry Hive: 64 bit Threat Removed
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\ Control, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\ Insertable, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\MiscStatus\ 1, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\ MiscStatus, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\ ProgID, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\ Programmable, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\ ToolboxBitmap32, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\ TypeLib, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\ Version, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\ VersionIndependentProgID, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\ {52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\ {52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}, Registry Hive: 64 bit Threat Removed
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{CDD67718-A430-4AB9-A939-83D9074B0038}\ ProgID, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{CDD67718-A430-4AB9-A939-83D9074B0038}\ Programmable, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{CDD67718-A430-4AB9-A939-83D9074B0038}\ TypeLib, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{CDD67718-A430-4AB9-A939-83D9074B0038}\ VersionIndependentProgID, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\ {CDD67718-A430-4AB9-A939-83D9074B0038}, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\ {CDD67718-A430-4AB9-A939-83D9074B0038}, Registry Hive: 64 bit Threat Removed
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{4764030F-2733-45B9-AE62-3D1F4F6F2861}\ ProgID, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{4764030F-2733-45B9-AE62-3D1F4F6F2861}\ Programmable, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{4764030F-2733-45B9-AE62-3D1F4F6F2861}\ TypeLib, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{4764030F-2733-45B9-AE62-3D1F4F6F2861}\ VersionIndependentProgID, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\ {4764030F-2733-45B9-AE62-3D1F4F6F2861}, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\ {4764030F-2733-45B9-AE62-3D1F4F6F2861}, Registry Hive: 64 bit Threat Removed
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{7D11E719-FF90-479C-B0D7-96EB43EE55D7}\ ProgID, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{7D11E719-FF90-479C-B0D7-96EB43EE55D7}\ Programmable, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{7D11E719-FF90-479C-B0D7-96EB43EE55D7}\ TypeLib, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{7D11E719-FF90-479C-B0D7-96EB43EE55D7}\ VersionIndependentProgID, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\ {7D11E719-FF90-479C-B0D7-96EB43EE55D7}, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\ {7D11E719-FF90-479C-B0D7-96EB43EE55D7}, Registry Hive: 64 bit Threat Removed
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{0F947660-8606-420A-BAC6-51B84DD22A47}\ Elevation, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{0F947660-8606-420A-BAC6-51B84DD22A47}\ ProgID, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{0F947660-8606-420A-BAC6-51B84DD22A47}\ Programmable, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{0F947660-8606-420A-BAC6-51B84DD22A47}\ TypeLib, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{0F947660-8606-420A-BAC6-51B84DD22A47}\ VersionIndependentProgID, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\ {0F947660-8606-420A-BAC6-51B84DD22A47}, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\WOW6432Node\CLSID\ {0F947660-8606-420A-BAC6-51B84DD22A47}, Registry Hive: 64 bit Threat Removed
Registry change: HKEY_CLASSES_ROOT\AppID\ {0F947660-8606-420A-BAC6-51B84DD22A47}, Registry Hive: 64 bit Repaired
Registry change: HKEY_CLASSES_ROOT\AppID\ {0F947660-8606-420A-BAC6-51B84DD22A47}, Registry Hive: 64 bit Threat Removed
Registry change: HKEY_USERS\S-1-5-21-4178908595-2914001671-1019688389-1001\Software\Microsoft\Internet Explorer\MenuExt\ idm הורד באמצעות->contexts, Registry Hive: 64 bit Threat Removed
Registry change: HKEY_USERS\S-1-5-21-4178908595-2914001671-1019688389-1001\Software\Microsoft\Internet Explorer\MenuExt\ הורד את כל הלינקים באמצעות IDM->contexts, Registry Hive: 64 bit Threat Removed
Registry change: HKEY_USERS\S-1-5-21-4178908595-2914001671-1019688389-1001\Software\DownloadManager\ maxID->maxID:388, Registry Hive: 64 bit Repaired
Registry change: HKEY_USERS\S-1-5-21-4178908595-2914001671-1019688389-1001\Software\DownloadManager\389\ ChList, Registry Hive: 64 bit Repaired
Registry change: HKEY_USERS\S-1-5-21-4178908595-2914001671-1019688389-1001\Software\DownloadManager\ 389->Status:5, Registry Hive: 64 bit Repaired
Registry change: HKEY_USERS\S-1-5-21-4178908595-2914001671-1019688389-1001\Software\DownloadManager\ 389, Registry Hive: 64 bit Repaired
Registry change: HKEY_USERS\S-1-5-21-4178908595-2914001671-1019688389-1001\Software\DownloadManager\ maxID->maxID:389, Registry Hive: 64 bit Repaired
Registry change: HKEY_USERS\S-1-5-21-4178908595-2914001671-1019688389-1001\Software\DownloadManager\390\ ChList, Registry Hive: 64 bit Repaired
Registry change: HKEY_USERS\S-1-5-21-4178908595-2914001671-1019688389-1001\Software\DownloadManager\ 390, Registry Hive: 64 bit Repaired
Registry change: HKEY_USERS\S-1-5-21-4178908595-2914001671-1019688389-1001\Software\Microsoft\Internet Explorer\MenuExt\ idm הורד באמצעות, Registry Hive: 64 bit Threat Removed
Registry change: HKEY_USERS\S-1-5-21-4178908595-2914001671-1019688389-1001\Software\Microsoft\Internet Explorer\MenuExt\ הורד את כל הלינקים באמצעות IDM, Registry Hive: 64 bit Threat Removed
Registry change: HKEY_USERS\S-1-5-21-4178908595-2914001671-1019688389-1001\Software\Microsoft\ Internet Explorer->DownloadUI, Registry Hive: 64 bit Threat Removed
Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\ Internet Explorer->DownloadUI, Registry Hive: 64 bit Threat Removed
____________________________

Startup Actions

\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}\InprocServer32 (Performed by c:\program files (x86)\internet download manager\idman.exe, PID:10448) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}\InprocServer32:ThreadingModel (Performed by c:\program files (x86)\internet download manager\idman.exe, PID:10448) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}\InprocServer32 (Performed by c:\program files (x86)\internet download manager\idman.exe, PID:10448) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}\InprocServer32:ThreadingModel (Performed by c:\program files (x86)\internet download manager\idman.exe, PID:10448) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}\InprocServer32 (Performed by c:\program files (x86)\internet download manager\idman.exe, PID:10448) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}\InprocServer32:ThreadingModel (Performed by c:\program files (x86)\internet download manager\idman.exe, PID:10448) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\InprocServer32 (Performed by c:\program files (x86)\internet download manager\idman.exe, PID:10448) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\InprocServer32:ThreadingModel (Performed by c:\program files (x86)\internet download manager\idman.exe, PID:10448) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{CDD67718-A430-4AB9-A939-83D9074B0038}\InprocServer32 (Performed by c:\program files (x86)\internet download manager\idman.exe, PID:10448) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{CDD67718-A430-4AB9-A939-83D9074B0038}\InprocServer32:ThreadingModel (Performed by c:\program files (x86)\internet download manager\idman.exe, PID:10448) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{4764030F-2733-45B9-AE62-3D1F4F6F2861}\InprocServer32 (Performed by c:\program files (x86)\internet download manager\idman.exe, PID:10448) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{4764030F-2733-45B9-AE62-3D1F4F6F2861}\InprocServer32:ThreadingModel (Performed by c:\program files (x86)\internet download manager\idman.exe, PID:10448) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{7D11E719-FF90-479C-B0D7-96EB43EE55D7}\InprocServer32 (Performed by c:\program files (x86)\internet download manager\idman.exe, PID:10448) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{7D11E719-FF90-479C-B0D7-96EB43EE55D7}\InprocServer32:ThreadingModel (Performed by c:\program files (x86)\internet download manager\idman.exe, PID:10448) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0F947660-8606-420A-BAC6-51B84DD22A47}\InprocServer32 (Performed by c:\program files (x86)\internet download manager\idman.exe, PID:10448) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0F947660-8606-420A-BAC6-51B84DD22A47}\InprocServer32:ThreadingModel (Performed by c:\program files (x86)\internet download manager\idman.exe, PID:10448) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}\InprocServer32 (Performed by c:\program files (x86)\internet download manager\idman.exe, PID:8196) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}\InprocServer32:ThreadingModel (Performed by c:\program files (x86)\internet download manager\idman.exe, PID:8196) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}\InprocServer32 (Performed by c:\program files (x86)\internet download manager\idman.exe, PID:8196) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}\InprocServer32:ThreadingModel (Performed by c:\program files (x86)\internet download manager\idman.exe, PID:8196) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}\InprocServer32 (Performed by c:\program files (x86)\internet download manager\idman.exe, PID:8196) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}\InprocServer32:ThreadingModel (Performed by c:\program files (x86)\internet download manager\idman.exe, PID:8196) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\InprocServer32 (Performed by c:\program files (x86)\internet download manager\idman.exe, PID:8196) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\InprocServer32:ThreadingModel (Performed by c:\program files (x86)\internet download manager\idman.exe, PID:8196) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{CDD67718-A430-4AB9-A939-83D9074B0038}\InprocServer32 (Performed by c:\program files (x86)\internet download manager\idman.exe, PID:8196) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{CDD67718-A430-4AB9-A939-83D9074B0038}\InprocServer32:ThreadingModel (Performed by c:\program files (x86)\internet download manager\idman.exe, PID:8196) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{4764030F-2733-45B9-AE62-3D1F4F6F2861}\InprocServer32 (Performed by c:\program files (x86)\internet download manager\idman.exe, PID:8196) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{4764030F-2733-45B9-AE62-3D1F4F6F2861}\InprocServer32:ThreadingModel (Performed by c:\program files (x86)\internet download manager\idman.exe, PID:8196) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{7D11E719-FF90-479C-B0D7-96EB43EE55D7}\InprocServer32 (Performed by c:\program files (x86)\internet download manager\idman.exe, PID:8196) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{7D11E719-FF90-479C-B0D7-96EB43EE55D7}\InprocServer32:ThreadingModel (Performed by c:\program files (x86)\internet download manager\idman.exe, PID:8196) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0F947660-8606-420A-BAC6-51B84DD22A47}\InprocServer32 (Performed by c:\program files (x86)\internet download manager\idman.exe, PID:8196) No action taken
\REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0F947660-8606-420A-BAC6-51B84DD22A47}\InprocServer32:ThreadingModel (Performed by c:\program files (x86)\internet download manager\idman.exe, PID:8196) No action taken
____________________________

System Settings Actions

Event: Process start (Performed by c:\program files (x86)\internet download manager\idman.exe, PID:10448) No action taken
(Performed by c:\program files (x86)\internet download manager\idman.exe, PID:10448) No action taken
Event: Process start (Performed by c:\program files (x86)\internet download manager\idman.exe, PID:1280) No action taken
(Performed by c:\program files (x86)\internet download manager\idman.exe, PID:1280) No action taken
Event: Process start (Performed by c:\program files (x86)\internet download manager\idman.exe, PID:8196) No action taken
____________________________

Suspicious Actions

(Performed by c:\program files (x86)\internet download manager\idman.exe, PID:10448) No action taken
(Performed by c:\program files (x86)\internet download manager\idman.exe, PID:1280) No action taken
____________________________


File Thumbprint - SHA:
Not available
File Thumbprint - MD5:
Not available

Kudos0

Re: SONAR.AM.C.P!g12 ?

Here is the technical support response of IDM Hello, This is a false detection. You may verify this file on virustotal.com: https://www.virustotal.com/#/file/77b90ac9081e7cfd7f08947732a16b25a6038e... Symantec has already fixed this false detection. Note that white listing may take up to 72 hours to take effect via Live Update. Also you may update virus definitions manually from Symantec to fix it immediately. Anyway you may safely allow this file to run. Hope it helps
Kudos0

Re: SONAR.AM.C.P!g12 ?

If you believe Norton made a mistaken detection, you may submit a dispute at. https://submit.symantec.com/false_positive/.

maybe, add information from Permalink & Permalink.

Kudos0

Re: SONAR.AM.C.P!g12 ?

GennadyKatz:
Here is the technical support response of IDM Hello, This is a false detection. You may verify this file on virustotal.com: https://www.virustotal.com/#/file/77b90ac9081e7cfd7f08947732a16b25a6038e... Symantec has already fixed this false detection. Note that white listing may take up to 72 hours to take effect via Live Update. Also you may update virus definitions manually from Symantec to fix it immediately. Anyway you may safely allow this file to run. Hope it helps

You appear to have submitted "c:\program files (x86)\internet download manager\uninstall.exe" rather than "c:\program files (x86)\internet download manager\IDMan.exe" or "c:\users\genge\appdata\local\temp\idm_setup_temp\idm1.tmp" or the installer for the software.

There were a lot of files detected since this was a behavior detection, so I'm not 100% sure which files are specifically best to send.

Kudos0

Re: SONAR.AM.C.P!g12 ?

Hi there bjm_ 

Yeah it was IDM 6.28 becasue i was submitted few days ago(Before release IDM 6.29 released on October 3rd) 

I've  submitted via IDM direct download link before release IDM 6.29. So i am going to try my luck today by installing IDM again. Let's see SONAR behavior now. Now it's close to 72 hours as they promised me.

Thank you 

Kudos0

Re: SONAR.AM.C.P!g12 ?

 Thanks NORTON 

As promised IDM works within 72 hours. I just installed it works. SONAR is calm now. 

Kudos0

Re: SONAR.AM.C.P!g12 ?

Hi,nuwantha  I have now installed IDM 6.29 Build 2

And after a few minutes. While using an program,NS blocked file idm.exe detect it as SONAR.AM.C.P!g12 ?  What you build?

Kudos0

Re: SONAR.AM.C.P!g12 ?

Hi GennadyKatz...

Previously it was IDM 6.29 build 1. After your reply i was updated to IDM 6.29 build 2. Its not detects as SONAR.AM.C.P!g12 or any other. I'm not sure but try again after run Live-Update manually. 

Thank you 

This thread is closed from further comment. Please visit the forum to start a new thread.