iobituninstaller.exe

IObit Uninstaller

IObit Information Technology

This is a setup and installation application. The file has been seen being downloaded from www.freenew.net and multiple other hosts.
Publisher:
IObit  (signed by IObit Information Technology)

Product:
IObit Uninstaller

Version:
5.2.5.126

MD5:
564a664e4a997c5f2d69f21d61982831

SHA-1:
790d341104c9cf046dd340b19a5d3607590fde17

SHA-256:
ee135729518db37423fd59b5f4f8ff4cd02ba518be9a129b699ea955ad785318

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/25/2024 4:15:25 PM UTC  (today)

File size:
12.3 MB (12,887,328 bytes)

Product version:
5.2.0.0

Copyright:
Copyright© 2005-2016

Trademarks:
IObit

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\iobituninstaller.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
12/22/2015 6:00:00 PM

Valid to:
3/23/2018 6:59:59 PM

Subject:
CN=IObit Information Technology, O=IObit Information Technology, L=Chengdu, S=Sichuan, C=CN

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
454A6CD2E1E63CA9D542DFDAB518FED9

File PE Metadata
Compilation timestamp:
1/26/2016 11:45:47 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
393216:iM4oySrx/SjPIUpDdihCYKu8xXtQONVQAsw0FS8gg:iDG/uLpihCdNtvr7Wgg

Entry address:
0xF9E3C

Entry point:
55, 8B, EC, 83, C4, F0, B8, 6C, 82, 4F, 00, E8, A4, EE, F0, FF, 33, C0, 55, 68, C7, 9E, 4F, 00, 64, FF, 30, 64, 89, 20, 6A, 00, 6A, 00, 6A, 00, 6A, 00, 68, E0, 9E, 4F, 00, 33, C9, BA, 10, 9F, 4F, 00, B8, 84, 9F, 4F, 00, E8, 94, 34, FD, FF, A1, 64, 2F, 50, 00, 8B, 00, E8, CC, DE, FA, FF, A1, 64, 2F, 50, 00, 8B, 00, BA, E0, 9E, 4F, 00, E8, 4B, D9, FA, FF, 8B, 0D, 80, 2D, 50, 00, A1, 64, 2F, 50, 00, 8B, 00, 8B, 15, AC, 2C, 4F, 00, E8, BB, DE, FA, FF, A1, 64, 2F, 50, 00, 8B, 00, E8, FF, DF, FA, FF, 33, C0, 5A...
 
[+]

Entropy:
7.8970

Developed / compiled with:
Microsoft Visual C++

Code size:
994 KB (1,017,856 bytes)

The file iobituninstaller.exe has been seen being distributed by the following 16 URLs.

&onid=2096&oid=3001-2096_4-75161625&rsid=cbsidownloadcomsite&sl=en&sc=us&topicguid=utilities/software-removal&topicbrcrm=&pid=14497976&mfgid=6271865&merid=6271865&ctype=dm&cval=NONE&devicetype=desktop&pguid=7abf556cf5aea1142c95c3a5&viewguid=bgjn5-zyzphWXqgiwzQOSHzRvMctZw7Miptt&destUrl=http://files.downloadnow.com/s/software/14/49/79/.../iobituninstaller.exe

&onid=2096&oid=3001-2096_4-75161625&rsid=cbsidownloadcomsite&sl=en&sc=us&topicguid=utilities/software-removal&topicbrcrm=&pid=14497976&mfgid=6271865&merid=6271865&ctype=dm&cval=NONE&devicetype=desktop&pguid=2028603584bf4ebacc9e79ed&viewguid=bOHuSngQOR@EqOQ9st0G-5g5woZS4TIMvFIK&destUrl=http://files.downloadnow.com/s/software/14/49/79/.../iobituninstaller.exe

&onid=2096&oid=3001-2096_4-75161625&rsid=cbsidownloadcomsite&sl=en&sc=us&topicguid=utilities/software-removal&topicbrcrm=&pid=14497976&mfgid=6271865&merid=6271865&ctype=dm&cval=NONE&devicetype=desktop&pguid=72d2a752306c1651510c2e41&viewguid=azJxRb-W0T2acQmc2oX0uonWzaHys-yRx5Ra&destUrl=http://software-files-a.cnet.com/s/software/14/49/79/.../iobituninstaller.exe

Scan iobituninstaller.exe - Powered by Reason Core Security