removeit.exe
RemoveIT Pro Ultra Edition by InCode Solutions
Warning 7 antivirus scanners has detected malware in various versions of removeit.exe.
Overview
removeit.exe has 2 known versions, the most recent one is 10.0.0.0. removeit.exe is run as a standard windows process with the logged in user's account privileges. By adding a startup entry to the run registry key, the file will be executed when the user logs into Windows. The average file size is about 2.4 MB. During the process's lifecycle, the typical CPU resource utilization is about 0.0011% including both foreground and background operations, the average private memory consumption is about 5.14 MB with the maximum memory reaching around 8.89 MB. Addionally, typically read and write I/O disk operations is about 51.03 KB per minute for reads and 89.95 KB per minute for writes.
Details |
File name: | removeit.exe |
Publisher: | InCode Solutions |
Product name: | RemoveIT Pro Ultra Edition |
Typical file path: | C:\Program Files\incode solutions\removeit pro 2012 ultra\removeit.exe |
Behaviors
(Note, the behaviors below are for all versions of removeit.exe, select a unique version for details.)
Startup files (user) run
Runs under the registry key 'HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
- 'RemoveIT Pro v7Ultra' → C:\Program Files\InCode Solutions\RemoveIT Pro v7 Ultra\removeit.exe
- 'RemoveIT Pro v9Ultra' → C:\Program Files\InCode Solutions\RemoveIT Pro 2012 Ultra\removeit.exe
Malware detections
Based on 40+ industry antivirus scanners, 7 of them detected the following malware.
Antivirus engine | Engine version | Detection | File version |
ByteHero |
1.0.0.1 |
Trojan-Downloader.Win32.DlfBfkg.ln |
10.0.0.0 |
Comodo Internet Security |
14938 |
Heur.Suspicious |
7.0.0.0 |
Dr.Web |
7.0.1.02210 |
DLOADER.Trojan |
10.0.0.0 |
McAfee |
5.400.1158 |
Artemis!539E507EAAFC |
10.0.0.0 |
McAfee Gateway Anti-Malware |
v2012.1-dat |
Artemis!539E507EAAFC |
10.0.0.0 |
Sophos |
4.73.0 TP |
Mal/Behav-027 |
10.0.0.0 |
VirusBuster |
14.2.49.1 |
Trojan.Hackdefend!LoNj55IeOcE |
10.0.0.0 |
All file variations of removeit.exe