iobituninstaler.exe

Uninstall Programs

IObit Information Technology

This is a self-extracting archive and installer. It runs as a scheduled task under the Windows Task Scheduler. This is installed with multiple programs including IObit Uninstaller and Advanced SystemCare 7. The file has been seen being downloaded from storage.dobreprogramy.pl and multiple other hosts a web site host known to distribute potentially unwanted software operated by dobreprogramy sp. z o.o..
Publisher:
IObit  (signed by IObit Information Technology)

Product:
Uninstall Programs

Version:
3.1.7.2405

MD5:
d52dc3cd5a3af6f0caa14a7fc79e95e3

SHA-1:
cb642b769126f48f77a50426076170ea0e599afb

SHA-256:
39ac03dca0242f11a776914675631d29aae1ffeaebfd28e3f51be2e50e27c3de

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 1:57:54 AM UTC  (today)

File size:
10.7 MB (11,201,344 bytes)

Product version:
3.1.0.0

Copyright:
Copyright(C) 2005-2014

Trademarks:
IObit

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\iobit uninstaller\iobituninstaler.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/15/2013 11:00:00 AM

Valid to:
2/15/2016 10:59:59 AM

Subject:
CN=IObit Information Technology, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=IObit Information Technology, L=Chengdu, S=Sichuan, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
11CADAF29DA4C3CB113BF1877B120103

File PE Metadata
Compilation timestamp:
1/13/2014 8:44:56 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
196608:PQfwybcDOBihVuuCW9A4jkSVhsMW2WMEcHfw9lZ6lvM+OBfn3AB/ywpXsv5:PdyADOBihVhCkuMWsBHm+0VBf3Yawxy

Entry address:
0x286AA8

Entry point:
55, 8B, EC, 83, C4, E4, 33, C0, 89, 45, E8, 89, 45, E4, 89, 45, EC, B8, D8, 44, 68, 00, E8, A1, 28, D8, FF, 33, C0, 55, 68, A0, 6B, 68, 00, 64, FF, 30, 64, 89, 20, 8D, 55, EC, B8, 01, 00, 00, 00, E8, 22, CA, D7, FF, 8B, 45, EC, BA, B8, 6B, 68, 00, E8, 0D, 03, D8, FF, 75, 52, E8, 36, 52, FE, FF, 84, C0, 74, 2F, 8D, 55, E4, B8, 02, 00, 00, 00, E8, FD, C9, D7, FF, 8B, 45, E4, 8D, 55, E8, E8, F6, 59, FE, FF, 8B, 55, E8, B8, A0, 3F, 6A, 00, E8, 81, FC, D7, FF, A1, A0, 3F, 6A, 00, E8, 83, 56, FE, FF, 68, CC, 6B...
 
[+]

Entropy:
7.7250

Developed / compiled with:
Microsoft Visual C++

Code size:
2.5 MB (2,645,504 bytes)

Scheduled Task
Task name:
Uninstaller_SkipUac_Administrator

Action:
iobituninstaler.exe \uninstallexplorer


The file iobituninstaler.exe has been discovered within the following programs.

360Amigo is registry optimizer. 360Amigo System Speedup bundles a branded version of the Conduit Toolbar, designed to deliver search based advertising and results. During installation the user is presented in some cases with the option to install the toolbar (on by default).
www.360amigo.com
53% remove it
Publisher's description - “Advanced SystemCare 7 provides automated and all-in-one PC care service with Malware Removal, Registry Fix, Privacy Protection, Performance Tune-up, and System Cleaning capabilities.”
www.iobit.com/advancedsystemcarepro.php
27% remove it
IObit Uninstaller  by IObit
Publisher's description - “Uninstall programs with IObit Uninstaller. The free software removal program can uninstall programs and clean leftovers thoroughly. As a pure uninstall program, IObit Uninstaller 2 features himself in the market without install required to remove programs.”
www.iobit.com
18% remove it
 
Powered by Should I Remove It?

The file iobituninstaler.exe has been seen being distributed by the following 44 URLs.

http://storage.dobreprogramy.pl/.../iobituninstaller3.1.exe

http://185.22.234.15/iobit-uninstaller.exe

Latest 30 of 44 download URLs

Scan iobituninstaler.exe - Powered by Reason Core Security