removeit.exe

RemoveIT.Pro Ultra Edition

Damjan Irgolič

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘RemoveIT Pro v9Ultra’.
Publisher:
InCode Solutions  (signed by Damjan Irgolič)

Product:
RemoveIT.Pro Ultra Edition

Version:
16.0.2.107

MD5:
c265002235c54bc2c278b83d2f56fbff

SHA-1:
f6fe7341f7cd0048cc4d6f41ca27c1dec4566c49

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/29/2024 10:39:31 PM UTC  (today)

File size:
2.6 MB (2,773,704 bytes)

Product version:
16.0.0.0

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\incode solutions\removeit.pro ultra\removeit.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
6/2/2016 4:00:00 AM

Valid to:
6/3/2017 3:59:59 AM

Subject:
CN=Damjan Irgolič, O=Damjan Irgolič, STREET=Žuknica 31, L=Kostrena, S=Rijeka, PostalCode=51221, C=HR

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00BB70E469C9B7EA1A116821B59A02DB9C

File PE Metadata
Compilation timestamp:
6/20/1992 2:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x157464

Entry point:
55, 8B, EC, B9, 16, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 53, 56, 57, B8, 5C, 6C, 55, 00, E8, 9C, 01, EB, FF, 8B, 1D, 4C, 7B, 57, 00, 33, C0, 55, 68, D4, 8A, 55, 00, 64, FF, 30, 64, 89, 20, 8D, 45, F0, E8, E4, 82, FF, FF, 8D, 45, F0, BA, EC, 8A, 55, 00, E8, 47, CD, EA, FF, 8B, 45, F0, E8, 03, 2B, EB, FF, 8D, 55, E8, B8, 01, 00, 00, 00, E8, A2, B6, EA, FF, 8B, 45, E8, 8D, 55, EC, E8, 73, 22, EB, FF, 8B, 45, EC, BA, 04, 8B, 55, 00, E8, 22, CE, EA, FF, 0F, 85, B6, 00, 00, 00, 8D, 55, E4, B8, 02, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
1.3 MB (1,415,168 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
RemoveIT Pro v9Ultra

Command:
C:\Program Files\incode solutions\removeit.pro ultra\removeit.exe


Scan removeit.exe - Powered by Reason Core Security