cfrecovery17.exe

Complete File Recovery

Ariolic Software Ltd

This is a setup program which is used to install the application. The file has been seen being downloaded from www.techspot.com and multiple other hosts.
Publisher:
Ariolic Software, Ltd.  (signed by Ariolic Software Ltd)

Product:
Complete File Recovery

Description:
Deleted file recovery

Version:
1, 7, 0, 140

MD5:
e1b1f2bc66794c89904bb332dc2683d3

SHA-1:
d4a12064331d7530a3fa37b31c420e31763f654a

SHA-256:
29a5b019120ec7199941f63529004394676fe5af4cd9764ab916e2f43836ba33

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 8:22:27 AM UTC  (today)

File size:
2.4 MB (2,503,168 bytes)

Product version:
1, 7, 0, 140

Copyright:
Copyright (C) 2007-2014 Ariolic Software, Ltd.

Original file name:
CFRecovery.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Digital Signature
Authority:
COMODO CA Limited

Valid from:
9/17/2013 1:00:00 AM

Valid to:
9/18/2014 12:59:59 AM

Subject:
CN=Ariolic Software Ltd, O=Ariolic Software Ltd, STREET=Stalevarov st 7/15, L=Zaporizhia, S=Zaporizhia, PostalCode=69035, C=UA

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
14B723390CE3C5D41A7F66C33FEEB0DD

File PE Metadata
Compilation timestamp:
9/14/2014 3:30:27 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:H7+QPAXxHloZlgGTgHf5S7fISLdQVWW4yOW+MoYyqkdCVjiAf:H7+dXxHmZl1gRKASHlW+MXyHCY

Entry address:
0x1000

Entry point:
68, 01, F0, 91, 00, E8, 01, 00, 00, 00, C3, C3, 01, 56, D1, FC, 52, 81, 9B, D1, 10, 96, 5E, 8D, 5A, EC, 00, DE, 3B, 37, D2, 21, DE, 51, 48, 2C, C6, 42, 33, 7E, D7, 93, DD, 5B, 05, 5F, 98, D1, 29, 02, EF, 5B, 6C, 6D, 3C, 2E, BB, 1B, A7, 55, C3, C1, 15, DC, 50, 94, BA, 52, 68, 32, 4C, 1E, A6, D7, 1C, AE, D7, 4D, 63, 0A, E5, 2D, 25, 21, A5, 15, BE, DC, CA, CF, 1B, 51, 9F, EC, C9, 02, 17, D9, 5E, 33, 0A, 2E, 52, B8, A1, 75, 76, E4, CC, 87, 23, 99, 6C, 6A, A3, 5E, E5, F9, 10, 5B, DF, 41, B8, 6D, 3E, CC, 1E, 97...
 
[+]

Entropy:
7.6931

Packer / compiler:
ASProtect v1.2x (New Strain)

Code size:
2.7 MB (2,839,040 bytes)

The file cfrecovery17.exe has been seen being distributed by the following 2 URLs.

http://www.techspot.com/downloads/downloadnow/.../?evp=0916bf02c1be30399289b475868dae34&file=1

Scan cfrecovery17.exe - Powered by Reason Core Security