uninstallpromote.exe

IObit

The executable uninstallpromote.exe has been detected as malware by 7 anti-virus scanners.
Publisher:
IObit

Version:
1.0.0.44

MD5:
6d3e39fe8104f158aa4125071f6e69fd

SHA-1:
acc5417560ebb4e0d8373f481039a5e046338410

SHA-256:
712cf4057b0e724fb3fb57d431260a7ec2e9a7c60409fac127db2fd87711c82f

Scanner detections:
7 / 68

Status:
Malware

Analysis date:
4/26/2024 12:42:24 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Malware.Heur.cM0@bezB!4fj
928

Avira AntiVirus
HEUR/Malware
7.11.163.92

Bitdefender
Gen:Malware.Heur.cM0@bezB!4fj
1.0.20.1015

Emsisoft Anti-Malware
Gen:Malware.Heur.cM0@bezB!4fj
8.14.07.22.09

F-Secure
Gen:Malware.Heur.cM0@bezB!4fj
11.2014-22-07_3

G Data
Gen:Malware.Heur.cM0@bezB!4fj
14.7.24

MicroWorld eScan
Gen:Malware.Heur.cM0@bezB!4fj
15.0.0.609

File size:
2 MB (2,130,944 bytes)

Product version:
2.0.0.0

Copyright:
Copyright(C) 2005-2014

Trademarks:
IObit

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\iobit\iobit uninstaller\uninstallpromote.exe

File PE Metadata
Compilation timestamp:
2/28/2014 11:49:26 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:ru4Kr+9C1KyN3n69QOTdoTHgchdKuZNKYe4UNIp:i4KK01KM3SQaIhdKuZe4UQ

Entry address:
0x11A040

Entry point:
55, 8B, EC, 83, C4, E4, 33, C0, 89, 45, E4, 89, 45, E8, 89, 45, EC, B8, 98, 7B, 51, 00, E8, ED, DE, EE, FF, 33, C0, 55, 68, 49, A1, 51, 00, 64, FF, 30, 64, 89, 20, A1, 20, 7B, 52, 00, 8B, 00, E8, 27, A1, F8, FF, 6A, 00, A1, 20, 7B, 52, 00, 8B, 00, 8B, 80, 70, 01, 00, 00, 50, E8, B6, EF, EE, FF, 8D, 55, EC, B8, 01, 00, 00, 00, E8, 75, 93, EE, FF, 8B, 45, EC, BA, 64, A1, 51, 00, E8, 00, 18, EF, FF, 84, C0, 74, 10, A1, 20, 7B, 52, 00, 8B, 00, 33, D2, E8, 4E, BC, F8, FF, EB, 0E, A1, 20, 7B, 52, 00, 8B, 00, B2...
 
[+]

Entropy:
6.8257

Developed / compiled with:
Microsoft Visual C++

Code size:
1.1 MB (1,147,904 bytes)

Remove uninstallpromote.exe - Powered by Reason Core Security