DeviceRemoverCleanup64.exe

DeviceRemoverCleanup64.exe

Copyright © 2008-2012 by Kerem Gümrükcü

This is a setup program which is used to install the application. The file has been seen being downloaded from www.pro-it-education.de.
Publisher:
Copyright © 2008-2012 by Kerem Gümrükcü

Product:
DeviceRemoverCleanup64.exe

Description:
Device Remover Cleanup Application. Helps cleaning-up Device Remover Instances.

Version:
1.0.0.2

MD5:
bba1d8402542c9ccbd18912244bc414e

SHA-1:
ddcf149d4c391daf7ea9cc8437a50396964d11e8

SHA-256:
01b6afcd8db31724f6563732715b07c59ed9ba47861c8a4983ddaf314ae9997e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/25/2024 3:40:25 PM UTC  (today)

File size:
50 KB (51,200 bytes)

Product version:
1.0.0.2

Copyright:
Copyright © 2008-2012 by Kerem Gümrükcü

Trademarks:
Copyright © 2008-2012 by Kerem Gümrükcü

Original file name:
DeviceRemoverCleanup64.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\device remover\tools\deviceremovercleanup64.exe

File PE Metadata
Compilation timestamp:
10/14/2012 9:11:14 AM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
2.50

CTPH (ssdeep):
768:WhGfER9rOjPLGl5alSl+ybb+rFjirxSPdDfFxJPqzB5+EUnfWJP:WhFR9rOjPKl5NXb6rFjI8HqzfJP

Entry address:
0x4920

Entry point:
53, 56, 48, 81, EC, 88, 00, 00, 00, B9, 00, 00, 00, 02, E8, ED, 0C, 00, 00, 48, 89, 05, 56, 67, 00, 00, E8, 41, 02, 00, 00, 85, C0, 75, 0F, B9, 01, 00, 00, 00, E8, F3, 00, 00, 00, E9, B8, 00, 00, 00, E8, B9, 04, 00, 00, E8, 04, 05, 00, 00, E8, BF, 09, 00, 00, E8, 8A, 0A, 00, 00, 48, 8D, 1D, 9B, 5F, 00, 00, 48, 8D, 05, 94, 5F, 00, 00, 48, 39, C3, 73, 12, FF, 13, 48, 83, C3, 08, 48, 8D, 05, 82, 5F, 00, 00, 48, 39, C3, 72, EE, C7, 44, 24, 5C, 00, 00, 00, 00, 48, 8D, 4C, 24, 20, FF, 15, 32, 71, 00, 00, 31, C9...
 
[+]

Code size:
21 KB (21,504 bytes)

The file DeviceRemoverCleanup64.exe has been seen being distributed by the following URL.

Scan DeviceRemoverCleanup64.exe - Powered by Reason Core Security