File name:

IObitUninstallerPortable_7.5.0.7.paf.exe

Full analysis: https://app.any.run/tasks/8fe6e668-4055-468d-849c-94ec5480f179
Verdict: Malicious activity
Threats:

Trojans are a group of malicious programs distinguished by their ability to masquerade as benign software. Depending on their type, trojans possess a variety of capabilities, ranging from maintaining full remote control over the victim’s machine to stealing data and files, as well as dropping other malware. At the same time, the main functionality of each trojan family can differ significantly depending on its type. The most common trojan infection chain starts with a phishing email.

Analysis date: June 10, 2021, 08:23:11
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
trojan
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

D0A545671BA205734251990208640D2A

SHA1:

6C5B2535F2C78BBC607363FC03E961E3BC92EEEF

SHA256:

DE846EFACF011DCBFD9CE21A063FD1711D4D4360D38111E8F4204F5E785E72F0

SSDEEP:

196608:9I6rqOBMlkOdqc7dL/2Dv7wYNONIcmNhU1AqpjXB4sMkB06+:TmO2lJ2DvMYND3NurM+06+

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • IObitUninstallerPortable_7.5.0.7.paf.exe (PID: 3240)
      • IObitUninstallerPortable.exe (PID: 3988)
      • IObitUninstallerPortable.exe (PID: 304)
      • Uninstaler_SkipUac.exe (PID: 3596)
      • IObitUninstaler.exe (PID: 3340)
    • Drops executable file immediately after starts

      • IObitUninstallerPortable_7.5.0.7.paf.exe (PID: 3240)
      • IObitUninstallerPortable.exe (PID: 3988)
      • IObitUninstallerPortable.exe (PID: 304)
    • Application was dropped or rewritten from another process

      • IObitUninstallerPortable.exe (PID: 3988)
      • IObitUninstallerPortable.exe (PID: 304)
      • Uninstaler_SkipUac.exe (PID: 3596)
      • IObitUninstaler.exe (PID: 3340)
    • Loads the Task Scheduler COM API

      • Uninstaler_SkipUac.exe (PID: 3596)
    • Steals credentials from Web Browsers

      • IObitUninstaler.exe (PID: 3340)
    • Actions looks like stealing of personal data

      • IObitUninstaler.exe (PID: 3340)
    • Connects to CnC server

      • IObitUninstaler.exe (PID: 3340)
  • SUSPICIOUS

    • Checks supported languages

      • IObitUninstallerPortable_7.5.0.7.paf.exe (PID: 3240)
      • IObitUninstallerPortable.exe (PID: 3988)
      • IObitUninstallerPortable.exe (PID: 304)
      • Uninstaler_SkipUac.exe (PID: 3596)
      • IObitUninstaler.exe (PID: 3340)
    • Reads the computer name

      • IObitUninstallerPortable_7.5.0.7.paf.exe (PID: 3240)
      • IObitUninstallerPortable.exe (PID: 3988)
      • IObitUninstallerPortable.exe (PID: 304)
      • Uninstaler_SkipUac.exe (PID: 3596)
      • IObitUninstaler.exe (PID: 3340)
    • Drops a file with too old compile date

      • IObitUninstallerPortable_7.5.0.7.paf.exe (PID: 3240)
    • Drops a file that was compiled in debug mode

      • IObitUninstallerPortable_7.5.0.7.paf.exe (PID: 3240)
    • Executable content was dropped or overwritten

      • IObitUninstallerPortable_7.5.0.7.paf.exe (PID: 3240)
      • IObitUninstallerPortable.exe (PID: 3988)
      • IObitUninstallerPortable.exe (PID: 304)
    • Drops a file with a compile date too recent

      • IObitUninstallerPortable_7.5.0.7.paf.exe (PID: 3240)
    • Application launched itself

      • IObitUninstallerPortable.exe (PID: 3988)
    • Creates files in the program directory

      • IObitUninstaler.exe (PID: 3340)
    • Creates a software uninstall entry

      • IObitUninstallerPortable.exe (PID: 304)
    • Searches for installed software

      • Uninstaler_SkipUac.exe (PID: 3596)
      • IObitUninstaler.exe (PID: 3340)
    • Reads the date of Windows installation

      • IObitUninstaler.exe (PID: 3340)
    • Creates a directory in Program Files

      • IObitUninstaler.exe (PID: 3340)
    • Creates files in the user directory

      • IObitUninstaler.exe (PID: 3340)
  • INFO

    • Dropped object may contain Bitcoin addresses

      • IObitUninstallerPortable_7.5.0.7.paf.exe (PID: 3240)
      • IObitUninstaler.exe (PID: 3340)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:01:30 04:57:41+01:00
PEType: PE32
LinkerVersion: 6
CodeSize: 26112
InitializedDataSize: 141824
UninitializedDataSize: 2048
EntryPoint: 0x34a5
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 7.5.0.7
ProductVersionNumber: 7.5.0.7
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
Comments: For additional details, visit PortableApps.com
CompanyName: PortableApps.com
FileDescription: IObit Uninstaller Portable
FileVersion: 7.5.0.7
InternalName: IObit Uninstaller Portable
LegalCopyright: 2007-2017 PortableApps.com, PortableApps.com Installer 3.5.8.0
LegalTrademarks: PortableApps.com is a registered trademark of Rare Ideas, LLC.
OriginalFileName: IObitUninstallerPortable_7.5.0.7.paf.exe
PortableAppscomAppID: IObitUninstallerPortable
PortableAppscomFormatVersion: 3.5.8
PortableAppscomInstallerVersion: 3.5.8.0
ProductName: IObit Uninstaller Portable
ProductVersion: 7.5.0.7

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 30-Jan-2018 03:57:41
Detected languages:
  • English - United States
Comments: For additional details, visit PortableApps.com
CompanyName: PortableApps.com
FileDescription: IObit Uninstaller Portable
FileVersion: 7.5.0.7
InternalName: IObit Uninstaller Portable
LegalCopyright: 2007-2017 PortableApps.com, PortableApps.com Installer 3.5.8.0
LegalTrademarks: PortableApps.com is a registered trademark of Rare Ideas, LLC.
OriginalFilename: IObitUninstallerPortable_7.5.0.7.paf.exe
PortableApps.comAppID: IObitUninstallerPortable
PortableApps.comFormatVersion: 3.5.8
PortableApps.comInstallerVersion: 3.5.8.0
ProductName: IObit Uninstaller Portable
ProductVersion: 7.5.0.7

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x000000D8

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 5
Time date stamp: 30-Jan-2018 03:57:41
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_LINE_NUMS_STRIPPED
  • IMAGE_FILE_LOCAL_SYMS_STRIPPED
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x00006409
0x00006600
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.41622
.rdata
0x00008000
0x0000138E
0x00001400
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.14383
.data
0x0000A000
0x00020358
0x00000600
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
4.0044
.ndata
0x0002B000
0x0002E000
0x00000000
IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
0
.rsrc
0x00059000
0x0001CF08
0x0001D000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
7.18824

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.28639
1249
UNKNOWN
English - United States
RT_MANIFEST
2
5.1717
9640
UNKNOWN
English - United States
RT_ICON
3
5.50995
4264
UNKNOWN
English - United States
RT_ICON
4
5.70014
3752
UNKNOWN
English - United States
RT_ICON
5
5.6488
2440
UNKNOWN
English - United States
RT_ICON
6
6.01856
2216
UNKNOWN
English - United States
RT_ICON
7
5.66656
1384
UNKNOWN
English - United States
RT_ICON
8
5.83657
1128
UNKNOWN
English - United States
RT_ICON
102
2.71813
180
UNKNOWN
English - United States
RT_DIALOG
103
2.80233
118
UNKNOWN
English - United States
RT_GROUP_ICON

Imports

ADVAPI32.dll
COMCTL32.dll
GDI32.dll
KERNEL32.dll
SHELL32.dll
USER32.dll
ole32.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
5
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start iobituninstallerportable_7.5.0.7.paf.exe iobituninstallerportable.exe iobituninstallerportable.exe uninstaler_skipuac.exe iobituninstaler.exe

Process information

PID
CMD
Path
Indicators
Parent process
304"C:\IObitUninstallerPortable\IObitUninstallerPortable.exe" /UAC:30138 /NCRCC:\IObitUninstallerPortable\IObitUninstallerPortable.exe
IObitUninstallerPortable.exe
User:
admin
Company:
PortableApps.com
Integrity Level:
HIGH
Description:
IObit Uninstaller Portable (PortableApps.com Launcher)
Exit code:
0
Version:
2.2.1.0
Modules
Images
c:\iobituninstallerportable\iobituninstallerportable.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3240"C:\Users\admin\AppData\Local\Temp\IObitUninstallerPortable_7.5.0.7.paf.exe" C:\Users\admin\AppData\Local\Temp\IObitUninstallerPortable_7.5.0.7.paf.exe
Explorer.EXE
User:
admin
Company:
PortableApps.com
Integrity Level:
MEDIUM
Description:
IObit Uninstaller Portable
Exit code:
0
Version:
7.5.0.7
Modules
Images
c:\users\admin\appdata\local\temp\iobituninstallerportable_7.5.0.7.paf.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3340"C:\IObitUninstallerPortable\App\uninstaller\IObitUninstaler.exe" /UninstallExplorerC:\IObitUninstallerPortable\App\uninstaller\IObitUninstaler.exe
Uninstaler_SkipUac.exe
User:
admin
Company:
IObit
Integrity Level:
HIGH
Description:
IObit Uninstaller
Exit code:
0
Version:
7.5.0.7
Modules
Images
c:\iobituninstallerportable\app\uninstaller\iobituninstaler.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\iobituninstallerportable\app\uninstaller\rtl120.bpl
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3596"C:\IObitUninstallerPortable\App\uninstaller\Uninstaler_SkipUac.exe" /UAC:30138 /NCRCC:\IObitUninstallerPortable\App\uninstaller\Uninstaler_SkipUac.exe
IObitUninstallerPortable.exe
User:
admin
Company:
IObit
Integrity Level:
HIGH
Description:
Uninstall Programs
Exit code:
0
Version:
7.0.1.28
Modules
Images
c:\iobituninstallerportable\app\uninstaller\uninstaler_skipuac.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\iobituninstallerportable\app\uninstaller\rtl120.bpl
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3988"C:\IObitUninstallerPortable\IObitUninstallerPortable.exe"C:\IObitUninstallerPortable\IObitUninstallerPortable.exe
IObitUninstallerPortable_7.5.0.7.paf.exe
User:
admin
Company:
PortableApps.com
Integrity Level:
MEDIUM
Description:
IObit Uninstaller Portable (PortableApps.com Launcher)
Exit code:
0
Version:
2.2.1.0
Modules
Images
c:\iobituninstallerportable\iobituninstallerportable.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
Total events
8 543
Read events
8 506
Write events
37
Delete events
0

Modification events

(PID) Process:(3240) IObitUninstallerPortable_7.5.0.7.paf.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3240) IObitUninstallerPortable_7.5.0.7.paf.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16B\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-2
Value:
Access the computers and devices that are on your network.
(PID) Process:(3240) IObitUninstallerPortable_7.5.0.7.paf.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:Browse For Folder Width
Value:
318
(PID) Process:(3240) IObitUninstallerPortable_7.5.0.7.paf.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:Browse For Folder Height
Value:
288
(PID) Process:(304) IObitUninstallerPortable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IObitUninstall
Operation:writeName:InstallLocation
Value:
C:\\IObitUninstallerPortable\\App\\uninstaller\\
(PID) Process:(304) IObitUninstallerPortable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IObitUninstall
Operation:writeName:UninstallString
Value:
"C:\\IObitUninstallerPortable\\App\\uninstaller\\unins000.exe"
(PID) Process:(304) IObitUninstallerPortable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IObitUninstall
Operation:writeName:DisplayVersion
Value:
7.5.0.7
(PID) Process:(304) IObitUninstallerPortable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IObitUninstall
Operation:writeName:DisplayIcon
Value:
C:\\IObitUninstallerPortable\\App\\uninstaller\\IObitUninstaler.exe
(PID) Process:(304) IObitUninstallerPortable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IObitUninstall
Operation:writeName:DisplayName
Value:
IObit Uninstaller
(PID) Process:(304) IObitUninstallerPortable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IObitUninstall
Operation:writeName:Publisher
Value:
IObit
Executable files
61
Suspicious files
7
Text files
121
Unknown types
14

Dropped files

PID
Process
Filename
Type
3240IObitUninstallerPortable_7.5.0.7.paf.exeC:\Users\admin\AppData\Local\Temp\nsj2DCF.tmp\LangDLL.dllexecutable
MD5:3DD80DFF583544514EEB3A5ED851A519
SHA256:86CFF5EACA76C49F924CB123D242FDCFD45AB99C4B638D3B8F4A8CFB1970AB5B
3240IObitUninstallerPortable_7.5.0.7.paf.exeC:\Users\admin\AppData\Local\Temp\nsj2DCF.tmp\modern-wizard.bmpimage
MD5:4DF53EFCAA2C52F39618B2AAD77BB552
SHA256:EE13539F3D66CC0592942EA1A4C35D8FD9AF67B1A7F272D0D791931E6E9CE4EB
3240IObitUninstallerPortable_7.5.0.7.paf.exeC:\Users\admin\AppData\Local\Temp\nsj2DCF.tmp\FindProcDLL.dllexecutable
MD5:BA4C1DFE226D573D516C0529F263011E
SHA256:2FFE1AC2555E822B4A383996168031E456F09F9CF3BB763FCCEE35BE178CF58A
3240IObitUninstallerPortable_7.5.0.7.paf.exeC:\Users\admin\AppData\Local\Temp\nsj2DCF.tmp\w7tbp.dllexecutable
MD5:9A3031CC4CEF0DBA236A28EECDF0AFB5
SHA256:53BB519E3293164947AC7CBD7E612F637D77A7B863E3534BA1A7E39B350D3C00
3240IObitUninstallerPortable_7.5.0.7.paf.exeC:\IObitUninstallerPortable\App\AppInfo\EULA.txttext
MD5:5B2B1AA779A9D57387F5893BCA2D6516
SHA256:DA5FD0C55C5B0A8097C3CC87B6E4B8421902C46408FC0C6E4303F25AE09889EB
3240IObitUninstallerPortable_7.5.0.7.paf.exeC:\IObitUninstallerPortable\App\readme.txttext
MD5:C6EF9BFB86C273EC5AA592DDD5480104
SHA256:6089179BA0BA4B01757D780FD98F7EDE96C924517927041C7011D5F93E44C92B
3240IObitUninstallerPortable_7.5.0.7.paf.exeC:\IObitUninstallerPortable\App\AppInfo\appicon_128.pngimage
MD5:242418292C0928CE5E02714410741FE8
SHA256:18A68B9605452EC677F527195791BDA1C57E75D0CD56FB9F46F6919C569491AD
3240IObitUninstallerPortable_7.5.0.7.paf.exeC:\IObitUninstallerPortable\App\AppInfo\appicon.icoimage
MD5:9D3B763D503613027FD318A666CF7AA4
SHA256:9359F9F5543DB4293B32BCB068CC170A8AB55919FFD2927FE14E71A95DF74824
3240IObitUninstallerPortable_7.5.0.7.paf.exeC:\IObitUninstallerPortable\App\AppInfo\Launcher\Custom.nshtext
MD5:8E15C5F80D772C21FF8FA3E8265D8E81
SHA256:03C5C3D5E379BEABA4B6F2C65C3B7AF5D13588DD94BB4C79569A84E4BA49EA90
3240IObitUninstallerPortable_7.5.0.7.paf.exeC:\IObitUninstallerPortable\App\AppInfo\appicon_16.pngimage
MD5:ACC564244633AF342A3367F4119BB6FD
SHA256:5D8EB9A70ECE6D232A76C76715682D438E4D1B8CC0B4CE66E181EDAA84E072B0
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
2
DNS requests
1
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3340
IObitUninstaler.exe
POST
200
152.199.20.140:80
http://download.iobit.com/news/version-check.ini
US
text
605 b
whitelisted
3340
IObitUninstaler.exe
GET
200
152.199.20.140:80
http://download.iobit.com/news/images/sale_04.png
US
image
3.05 Kb
whitelisted
3340
IObitUninstaler.exe
GET
200
152.199.20.140:80
http://download.iobit.com/news/images/sale_04.png
US
image
3.05 Kb
whitelisted
3340
IObitUninstaler.exe
POST
200
152.199.20.140:80
http://download.iobit.com/news/unins/v7/unins7newsfree.dat
US
text
4.80 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3340
IObitUninstaler.exe
152.199.20.140:80
download.iobit.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
malicious

DNS requests

Domain
IP
Reputation
download.iobit.com
  • 152.199.20.140
whitelisted

Threats

PID
Process
Class
Message
3340
IObitUninstaler.exe
A Network Trojan was detected
AV TROJAN Bancos Variant C2 Checkin 2
Process
Message
Uninstaler_SkipUac.exe
Params /UAC:30138
Uninstaler_SkipUac.exe
TaskName Uninstaller_SkipUac_admin
Uninstaler_SkipUac.exe
CheckU3Task 0
Uninstaler_SkipUac.exe
U3Task not found
Uninstaler_SkipUac.exe
U3Path C:\\IObitUninstallerPortable\\App\\uninstaller\\IObitUninstaler.exe
Uninstaler_SkipUac.exe
ShellExecute(0,,PChar(U3Path),/UninstallExplorer,nil,SW_NORMAL);
Uninstaler_SkipUac.exe
ShellExecute ok
IObitUninstaler.exe
VerifLicense:ALicenseFile:C:\Program Files\Common Files\IObit\IObit Uninstaller\
IObitUninstaler.exe
VerifLicense:Result:raFree
IObitUninstaler.exe
Action.Count: 6