iobituninstaller.exe

IObit Uninstaller

IObit Information Technology

This is a setup and installation application. The file has been seen being downloaded from dw.uptodown.com and multiple other hosts.
Publisher:
IObit  (signed by IObit Information Technology)

Product:
IObit Uninstaller

Version:
5.4.0.118

MD5:
fd09fb401ac059a472f9f9d50d2eb864

SHA-1:
3c6836e45fffb843c1ede37a2942e5bf030f2431

SHA-256:
ca43ebd93f8972ea4336bff81d37b7326a33521a992aa428f3eee21182ada2fe

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/18/2025 3:14:19 AM UTC  (today)

File size:
12.7 MB (13,354,784 bytes)

Product version:
5.4.0.0

Copyright:
Copyright© 2005-2016

Trademarks:
IObit

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\iobituninstaller.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
12/23/2015 1:00:00 AM

Valid to:
3/24/2018 12:59:59 AM

Subject:
CN=IObit Information Technology, O=IObit Information Technology, L=Chengdu, S=Sichuan, C=CN

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
454A6CD2E1E63CA9D542DFDAB518FED9

File PE Metadata
Compilation timestamp:
5/27/2016 6:40:13 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
393216:YM4o6iw0GxMOWmontCrWtdF04jW0L7sVEG:YL04bRQtEWtj7jW0PsV

Entry address:
0xF9E3C

Entry point:
55, 8B, EC, 83, C4, F0, B8, 00, 83, 4F, 00, E8, A4, EE, F0, FF, 33, C0, 55, 68, C7, 9E, 4F, 00, 64, FF, 30, 64, 89, 20, 6A, 00, 6A, 00, 6A, 00, 6A, 00, 68, E0, 9E, 4F, 00, 33, C9, BA, 10, 9F, 4F, 00, B8, 84, 9F, 4F, 00, E8, 94, 34, FD, FF, A1, 64, 2F, 50, 00, 8B, 00, E8, CC, DE, FA, FF, A1, 64, 2F, 50, 00, 8B, 00, BA, E0, 9E, 4F, 00, E8, 4B, D9, FA, FF, 8B, 0D, 80, 2D, 50, 00, A1, 64, 2F, 50, 00, 8B, 00, 8B, 15, 64, 2C, 4F, 00, E8, BB, DE, FA, FF, A1, 64, 2F, 50, 00, 8B, 00, E8, FF, DF, FA, FF, 33, C0, 5A...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
994 KB (1,017,856 bytes)

The file iobituninstaller.exe has been seen being distributed by the following 10 URLs.

https://dw.uptodown.com/dwn/NZse7bq7i6okZDJR4HdPxMQeNgjxCkYzP5jAUR8MHNXEwdpTusD0uOde9hHaAUYnUKceZeXelUXN3swxoEunrUKYjEd18G7_PyxFoTarcQA7AYr2b7WATTBYKALZljjN/ZTVH8ilkYJaNRME6IwhM1BluVeF4OqWw9r2yotkXGcDcmqL-WUOPs11oeDEYmoaNF5ETxdL15DR7nrvNlsq3_QXnNx1L7AZE3zBtiYQ7g1rLyqPhGmkq-xAO0N6LO5UR/-_KmCWUZ31-oRcqE6F0y-OrtgBQi0E4Wlvc-f4ax7WJ3wCPSLMOxzJ_TuCFzxi_yyV8TFcZ1sHpc7OaxqeWOrJ7es0p6PJYS5TgwFq2KcGK9bzyserRjWllqEdgR09ZV/.../

http://www.freenew.net/.../downApp.htm?platform=windows&id=68873&toUrl=1d06183455584139190a0a0117422d00150738470d04185d0828401e012e001a1e1b1b02371b1602200c1c45100a09

https://dw.uptodown.com/dwn/TP2gCzXYo72xMuPW1ofDiIy010VsiZQqVq7Gt1BzZWDvjv76gDHqb7MqgpNpexBlSryrMvTR2vWbOOyXA8IScTp0eLFD6u447Vrus014JHH6wbAee8xwqBipY1LBx5Uk/fgUauKbB29R_kfygdwOus9lrVXaHv0lvG4JBETBiHb7wfqAuywBHlx5fvesJ3LuZh93--HT5cVikozLz9NfU5jrtiW_lh2neu9Z_HdxTn8xtW_L_Tx65dxuFfpdmIYHs/NF6riggb9rgl5_nGRM3AKOzJf9WtaeIp-MHkUZlIdDxVm-EOGZ26zs58xPfnIsFSCds1zZ2-JJdP3v1cnU-KNS8dlUd3rFOj3UjTiy5aE2VHbYNgQexQu0B8uPFYk_9r/.../

http://dl.cdn.chip.de/downloads/.../iobituninstaller_5.4.0.exe

Scan iobituninstaller.exe - Powered by Reason Core Security