× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: 865450f02e35225fa83e9f54d0e217d69ec53a72818fd5b7fcbe550382c8c447
File name: iobituninstaller.exe_e_1274747398
Detection ratio: 0 / 41
Analysis date: 2010-05-24 22:28:37 UTC ( 3 years, 11 months ago ) View latest
Probably harmless! There are strong indicators suggesting that this file is safe to use.
Antivirus Result Update
AVG 20100524
AhnLab-V3 20100522
AntiVir 20100524
Antiy-AVL 20100524
Authentium 20100523
Avast 20100524
Avast5 20100524
BitDefender 20100524
CAT-QuickHeal 20100524
ClamAV 20100524
Comodo 20100524
DrWeb 20100524
F-Prot 20100523
F-Secure 20100524
Fortinet 20100523
GData 20100524
Ikarus 20100524
Jiangmin 20100524
Kaspersky 20100524
McAfee 20100524
McAfee-GW-Edition 20100524
Microsoft 20100524
NOD32 20100524
Norman 20100524
PCTools 20100524
Panda 20100524
Prevx 20100524
Rising 20100524
Sophos 20100524
Sunbelt 20100524
Symantec 20100524
TheHacker 20100524
TrendMicro 20100524
TrendMicro-HouseCall 20100524
VBA32 20100522
ViRobot 20100524
VirusBuster 20100524
a-squared 20100510
eSafe 20100524
eTrust-Vet 20100524
nProtect 20100524
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.
Authenticode signature block
Copyright
Copyright(C) 2005-2010

Publisher IObit Information Technology
Product IObit Uninstaller
File version 1.1.6.0
Description IObit Uninstaller
Signature verification Signed file, verified signature
Signing date 11:16 AM 5/11/2010
Signers
[+] IObit Information Technology
Status Certificate out of its validity period
Valid from 1:00 AM 12/8/2009
Valid to 12:59 AM 1/5/2013
Valid usage Code Signing
Algorithm SHA1
Thumbrint 4F5DF101212BB9BF7E1F2EE987DB70AC3E885F57
Serial number 2B 8F 44 22 6C 2D 9E 0E DF 57 65 B0 D7 A2 1B 51
[+] VeriSign Class 3 Code Signing 2009-2 CA
Status Valid
Valid from 1:00 AM 5/21/2009
Valid to 12:59 AM 5/21/2019
Valid usage Client Auth, Code Signing
Algorithm SHA1
Thumbrint 12D4872BC3EF019E7E0B6F132480AE29DB5B1CA3
Serial number 65 52 26 E1 B2 2E 18 E1 59 0F 29 85 AC 22 E7 5C
[+] VeriSign Class 3 Public Primary Certification Authority (PCA3 G1 SHA1)
Status Valid
Valid from 1:00 AM 1/29/1996
Valid to 12:59 AM 8/3/2028
Valid usage Server Auth, Client Auth, Email Protection, Code Signing
Algorithm SHA1
Thumbrint A1DB6393916F17E4185509400415C70240B0AE6B
Serial number 3C 91 31 CB 1F F6 D0 1B 0E 9A B8 D0 44 BF 12 BE
Counter signers
[+] VeriSign Time Stamping Services Signer - G2
Status Certificate out of its validity period
Valid from 1:00 AM 6/15/2007
Valid to 12:59 AM 6/15/2012
Valid usage Timestamp Signing
Algorithm SHA1
Thumbrint ADA8AAA643FF7DC38DD40FA4C97AD559FF4846DE
Serial number 38 25 D7 FA F8 61 AF 9E F4 90 E7 26 B5 D6 5A D5
[+] VeriSign Time Stamping Services CA
Status Certificate out of its validity period
Valid from 1:00 AM 12/4/2003
Valid to 12:59 AM 12/4/2013
Valid usage Timestamp Signing
Algorithm SHA1
Thumbrint F46AC0C6EFBB8C6A14F55F09E2D37DF4C0DE012D
Serial number 47 BF 19 95 DF 8D 52 46 43 F7 DB 6D 48 0D 31 A4
[+] Thawte Timestamping CA
Status Valid
Valid from 1:00 AM 1/1/1997
Valid to 12:59 AM 1/1/2021
Valid usage Timestamp Signing
Algorithm MD5
Thumbrint BE36A4562FB2EE05DBB3D32323ADF445084ED656
Serial number 00
Packers identified
F-PROT UPX
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2010-05-11 10:02:28
Entry Point 0x001C0A20
Number of sections 3
PE sections
PE imports
VirtualFree
ExitProcess
VirtualProtect
LoadLibraryA
VirtualAlloc
GetProcAddress
URLDownloadToFileW
RegFlushKey
ImageList_Add
GetSaveFileNameW
SaveDC
AlphaBlend
CoInitialize
VariantCopy
SHGetMalloc
VerQueryValueW
timeGetTime
Number of PE resources by type
RT_BITMAP 49
RT_GROUP_CURSOR 25
RT_STRING 25
RT_CURSOR 25
RT_RCDATA 8
RT_ICON 3
RT_DIALOG 2
RT_MANIFEST 1
RT_VERSION 1
RT_GROUP_ICON 1
Number of PE resources by language
NEUTRAL 62
ENGLISH US 58
RUSSIAN 14
CHINESE SIMPLIFIED 6
ExifTool file metadata
CodeSize
655360

UninitializedDataSize
1179648

LinkerVersion
2.25

ImageVersion
0.0

FileSubtype
0

FileVersionNumber
1.1.6.0

LanguageCode
English (U.S.)

FileFlagsMask
0x003f

CharacterSet
Windows, Latin1

InitializedDataSize
28672

MIMEType
application/octet-stream

LegalCopyright
Copyright(C) 2005-2010

FileVersion
1.1.6.0

TimeStamp
2010:05:11 11:02:28+01:00

FileType
Win32 EXE

PEType
PE32

SubsystemVersion
5.0

FileAccessDate
2014:04:17 01:34:16+01:00

ProductVersion
1.1.0.0

FileDescription
IObit Uninstaller

OSVersion
5.0

FileCreateDate
2014:04:17 01:34:16+01:00

FileOS
Win32

Subsystem
Windows GUI

MachineType
Intel 386 or later, and compatibles

CompanyName
IObit

LegalTrademarks
IObit

ProductName
IObit Uninstaller

ProductVersionNumber
1.1.6.0

EntryPoint
0x1c0a20

ObjectFileType
Executable application

Compressed bundles
File identification
MD5 9a1e76209115d9199d8eaa6466b7486c
SHA1 1f94654e5df051ae57ab454449bfab18bf29d4cf
SHA256 865450f02e35225fa83e9f54d0e217d69ec53a72818fd5b7fcbe550382c8c447
ssdeep
12288:/wV4yxLAXv36i19cTpiEeabfYgwPdiZVhM43suryUSQQOzl/Mggrfm4:IV4yxMfKijEe2YgdrMTu2Hmzxsm4

imphash 246e2f93cee1a8e2f38c8401523e81e0
File size 673.4 KB ( 689560 bytes )
File type Win32 EXE
Magic literal
PE32 executable for MS Windows (GUI) Intel 80386 32-bit

TrID UPX compressed Win32 Executable (41.1%)
Win32 EXE Yoda's Crypter (35.7%)
Win32 Dynamic Link Library (generic) (8.8%)
Win32 Executable (generic) (6.0%)
Win16/32 Executable Delphi generic (2.7%)
Tags
peexe software-collection upx signed mz

VirusTotal metadata
First submission 2010-05-12 03:32:04 UTC ( 3 years, 11 months ago )
Last submission 2014-02-18 12:41:23 UTC ( 2 months ago )
File names 9a1e76209115d9199d8eaa6466b7486c
_Uninstaller_IObit_Uninstaller_1.
smona132031752613915739155
IOBIT - iobituninstaller.exe
1F94654E5DF051AE57AB454449BFAB18BF29D4CF
78393_iobit_uninstaller_11.exe
iobit_advanced_uninstaller_1.1.ex
smona131515916637625280941
iobituninstaller_v_1_1.exe
smona131824663751456776351
iobit-uninstaller_iobit_advanced_uninstaller_1.1_anglais_322480.exe
uninstaller.exe
iobituninstaller.exe
IOBit Uninstaller 1.1Without installation 071210.exe
iobituninstaller.exe_e_1274747398
IObit Uninstaller.exe
file-1117117_exe
iobituninstaller(1).exe
Advanced Uninstaller.exe
IObitUninstaller.exe
Sut_SoftUninstaller.exe
20587-iobituninstaller.exe
iobituninstaller.exe
7545149
Iobit_Uninstaller_1.1.6.0.exe
Advanced heuristic and reputation engines
ClamAV PUA
Possibly Unwanted Application. While not necessarily malicious, the scanned file presents certain characteristics which depending on the user policies and environment may or may not represent a threat. For full details see: http://www.clamav.net/index.php?s=pua&lang=en .

No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!