| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Mar-07 06:15:49 |
| Detected languages |
English - United States
|
| Comments | Please visit http://www.internetdownloadmanager.com |
| CompanyName | Tonec Inc. |
| FileDescription | Internet Download Manager installer |
| FileVersion | 6, 42, 63, 1 |
| InternalName | installer |
| LegalCopyright | © 1999-2026. Tonec FZE. All rights reserved. |
| LegalTrademarks | Internet Download Manager (IDM) |
| OriginalFilename | installer.exe |
| ProductName | Internet Download Manager installer |
| ProductVersion | 6, 42, 63, 1 |
| Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: Tonec Inc.
Issuer: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 |
| Safe | VirusTotal score: 0/71 (Scanned on 2026-08-02 06:13:16) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xe8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2026-Mar-07 06:15:49 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 9.0 |
| SizeOfCode | 0xb800 |
| SizeOfInitializedData | 0xc800 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00005B7A (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0xd000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x1b000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0xbe4b9f |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x400000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| ADVAPI32.dll |
RegDeleteValueW
RegQueryValueExW RegOpenKeyExA RegCloseKey |
|---|---|
| USER32.dll |
FindWindowA
ShowWindow SetForegroundWindow CreateDialogParamA SetWindowTextA GetMessageA TranslateMessage DispatchMessageA wsprintfW DestroyWindow PostQuitMessage wsprintfA MessageBoxA SendMessageA |
| SHELL32.dll |
SHBrowseForFolderW
SHGetPathFromIDListW |
| KERNEL32.dll |
LCMapStringW
LCMapStringA GetStringTypeW MultiByteToWideChar GetStringTypeA GetLocaleInfoA GetDiskFreeSpaceW GetProcAddress GetModuleHandleA FreeLibrary LoadLibraryA GetCurrentProcess LocalFree lstrlenA CloseHandle WriteFile SetFilePointer CreateFileW FormatMessageA GetLastError CreateThread CreateProcessW GetModuleFileNameW GetExitCodeThread WaitForSingleObject CreateDirectoryW GetFileAttributesW GetTempPathW GetVersionExA ExitProcess CreateMutexA ExitThread MapViewOfFile SetFileTime GetFileTime CreateFileMappingA GetFileSize UnmapViewOfFile RtlUnwind HeapFree GetCommandLineA GetStartupInfoA TerminateProcess UnhandledExceptionFilter SetUnhandledExceptionFilter IsDebuggerPresent GetModuleHandleW TlsGetValue TlsAlloc TlsSetValue TlsFree InterlockedIncrement SetLastError GetCurrentThreadId InterlockedDecrement HeapAlloc RaiseException HeapCreate VirtualFree DeleteCriticalSection LeaveCriticalSection EnterCriticalSection VirtualAlloc HeapReAlloc Sleep GetStdHandle GetModuleFileNameA FreeEnvironmentStringsA GetEnvironmentStrings FreeEnvironmentStringsW WideCharToMultiByte GetEnvironmentStringsW SetHandleCount GetFileType QueryPerformanceCounter GetTickCount GetCurrentProcessId GetSystemTimeAsFileTime GetCPInfo GetACP GetOEMCP IsValidCodePage HeapSize InitializeCriticalSectionAndSpinCount |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 6.42.63.1 |
| ProductVersion | 6.42.63.1 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| Comments | Please visit http://www.internetdownloadmanager.com |
| CompanyName | Tonec Inc. |
| FileDescription | Internet Download Manager installer |
| FileVersion (#2) | 6, 42, 63, 1 |
| InternalName | installer |
| LegalCopyright | © 1999-2026. Tonec FZE. All rights reserved. |
| LegalTrademarks | Internet Download Manager (IDM) |
| OriginalFilename | installer.exe |
| ProductName | Internet Download Manager installer |
| ProductVersion (#2) | 6, 42, 63, 1 |
| Resource LangID | English - United States |
|---|
| Size | 0x48 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x412190 |
| SEHandlerTable | 0x40f800 |
| SEHandlerCount | 7 |
| XOR Key | 0x878f2bba |
|---|---|
| Unmarked objects | 0 |
| ASM objects (VS2008 SP1 build 30729) | 19 |
| Imports (VS2012 build 50727 / VS2005 build 50727) | 9 |
| Total imports | 119 |
| C++ objects (VS2008 SP1 build 30729) | 38 |
| C objects (VS2008 SP1 build 30729) | 90 |
| Linker (VS2008 build 21022) | 1 |
| Resource objects (VS2008 SP1 build 30729) | 1 |
No comments yet.