Should I block it?
90% of PCs block this file from running.
Possible reason:
Multiple malware detections
Additional versions
Relationships
removeit.exe
RemoveIT Pro Ultra Edition by InCode Solutions
Version: | 10.0.0.0 |
MD5: | 539e507eaafcde90294a606cd412607f |
SHA1: | 81fa02c5a5b5f89949c93eb828536fd47405c277 |
SHA256: | 765ad2955c6cab5d0ec3b87759e8625c65385bc990ceec73755a5b3d16b3ed27 |
Warning 6 antivirus scanners has detected malware.
Overview
removeit.exe is malware that executes as a process with the local user's privileges usually within the context of Windows Explorer. It is set to be run when the PC boots and the user logs into Windows (added to the Run registry key for the current user).
Details
File name: | removeit.exe |
Publisher: | InCode Solutions |
Product name: | RemoveIT Pro Ultra Edition |
Typical file path: | C:\Program Files\incode solutions\removeit pro 2012 ultra\removeit.exe |
File version: | 10.0.0.0 |
Size: | 2.55 MB (2,677,760 bytes) |
Digital DNA |
PE subsystem: | Windows GUI |
File packed: | No |
.NET CLR: | No |
More details
Behaviors
Startup files (user) run
Runs under the registry key 'HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
- 'RemoveIT Pro v7Ultra' → C:\Program Files\InCode Solutions\RemoveIT Pro v7 Ultra\removeit.exe
- 'RemoveIT Pro v9Ultra' → C:\Program Files\InCode Solutions\RemoveIT Pro 2012 Ultra\removeit.exe
Network connections
[TCP] da.97.79ae.static.theplanet.com (174.121.151.218:80)
Malware detections
Based on 40+ industry antivirus scanners, 6 of them detected the following malware.
Antivirus engine | Engine version | Detection |
ByteHero |
1.0.0.1 |
Trojan-Downloader.Win32.DlfBfkg.ln |
Dr.Web |
7.0.1.02210 |
DLOADER.Trojan |
McAfee |
5.400.1158 |
Artemis!539E507EAAFC |
McAfee Gateway Anti-Malware |
v2012.1-dat |
Artemis!539E507EAAFC |
Sophos |
4.73.0 TP |
Mal/Behav-027 |
VirusBuster |
14.2.49.1 |
Trojan.Hackdefend!LoNj55IeOcE |
Resource utilization
(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
CPU |
Total CPU: | 0.00120838% | |
Kernel CPU: | 0.00067430% | |
User CPU: | 0.00053408% | |
Kernel CPU time: | 25,803 ms/min | |
CPU cycles: | 19,933,937/sec | |
Memory |
Private memory: | 5.86 MB | |
Private (maximum): | 5.01 MB | |
Private (minimum): | 1.23 MB | |
Non-paged memory: | 5.86 MB | |
Virtual memory: | 98.81 MB | |
Virtual memory (peak): | 157.02 MB | |
Working set: | 4.7 MB | |
Working set (peak): | 16.18 MB | |
Page faults: | 35,215,695/min | |
I/O |
I/O read transfer: | 51.03 KB/sec | |
I/O read operations: | 434/sec | |
I/O write transfer: | 89.95 KB/sec | |
I/O write operations: | 23/sec | |
I/O other transfer: | 7.44 KB/sec | |
I/O other operations: | 360/sec | |
Resource allocations |
Threads: | 16 | |
Handles: | 267 | |
GUI GDI count: | 365 | |
GUI GDI peak: | 375 | |
GUI USER count: | 337 | |
GUI USER peak: | 343 | |
Process properties
Distribution by Windows OS
OS version | distribution |
Windows 7 Home Premium |
50.00% |
|
Microsoft Windows XP |
50.00% |
|
Distribution by country
Finland installs about 50.00% of RemoveIT Pro Ultra Edition.