pandorarecovery2.1.1setup.exe

Pandora Corp

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
Publisher:
Pandora Corp  (signed and verified)

MD5:
105e1590c9bd7d2ef7c57b20390b5fc3

SHA-1:
4638bf9cfd9e0b8b4b7c613b83297ac0ac7c5701

SHA-256:
282475eb3a116ca07717fba16ad701f1c8d94d8ad4e48ac590ee38ee8e8cd7ac

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 2:32:35 AM UTC  (today)

File size:
3.1 MB (3,267,488 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\pandorarecovery2.1.1setup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
12/2/2008 6:00:00 PM

Valid to:
12/7/2009 5:59:59 PM

Subject:
CN=Pandora Corp, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Pandora Corp, S=Nevada, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0ACF71615F1F75854906D92ABFDACD4F

File PE Metadata
Compilation timestamp:
11/12/2005 10:03:57 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:3gM5sOldEEfOz5GBSVpAEay8B/yWvdPhU:N1dNq5GBkpAEay8BFvZhU

Entry address:
0x34E2

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, F6, 57, 89, 74, 24, 18, BB, B0, 97, 40, 00, 89, 74, 24, 10, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 56, FF, 15, 90, 72, 40, 00, A3, D0, 5E, 42, 00, 56, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 56, 68, C0, 03, 42, 00, FF, 15, 6C, 71, 40, 00, 68, A0, 97, 40, 00, 68, 20, 56, 42, 00, E8, F9, 28, 00, 00, BD, 00, C4, 42, 00, BF, 00, 04, 00, 00, 55, 57, FF, 15, B4, 70, 40, 00, E8, 5F, FF, FF, FF, 85, C0, 75, 24, 68, FB, 03, 00, 00, 55, FF, 15, 58, 71, 40, 00, 68, 98, 97...
 
[+]

Entropy:
7.9965

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file pandorarecovery2.1.1setup.exe has been discovered within the following programs.

KoolPlaya  by AKi-Software
About 3% of users remove it
Publisher's description - “Pandora Mobile Recovery is a portable version of Pandora Recovery that requires no installation and is distributed on a 1 GB USB thumb drive as part of the Pandora PowerPack.”
www.pandorarecovery.com
About 5% of users remove it
 
Powered by Should I Remove It?

The file pandorarecovery2.1.1setup.exe has been seen being distributed by the following 50 URLs.

http://gsf-cf.softonic.com/463/8bf/.../file?SD_used=0&channel=WEB&fdh=no&id_file=61540&instance=softonic_it&type=PROGRAM&Expires=1428468886&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=EZIAbhYic3zoS4c-7uANj63QdOQs9qF3AFMCACPINxAO2QU~ngwjrD0FBllvRg7M-zMbkMp-lXrOlDWC6Q5XDbw62PclXDNkEpLbCCEiUUC2qwiv9OmeybwdIWLrL8I3cjpDW9ZCgDrrPKhVxY94fLt0nCRbTcy8NYVYXWzlH2g_&filename=PandoraRecovery.exe

http://gsf-cf.softonic.com/463/8bf/.../file?SD_used=0&channel=WEB&fdh=no&id_file=61540&instance=softonic_es&type=PROGRAM&Expires=1461742109&Signature=QRWetSUVUN5XptRqZEmuxdsQYLZWuNWML6UV~jBA5GBzwBSHIK682R5XEOD0CPiUuDBgON1drCHgmc-moRufS5t-jmYV0tXBKHf2buH1t8MjoEL6YI-7BQBqKMcm-7JUC4~47LDl9ENzuZNPBDmWNRv7fm8bmUvScFAZZ3Usa2Q_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=PandoraRecovery.exe

http://gsf-cf.softonic.com/463/8bf/.../file?SD_used=0&channel=WEB&fdh=no&id_file=61540&instance=softonic_es&type=PROGRAM&Expires=1481936383&Signature=F4DG00Ouhx6V4klLy~srtdiJFigByGLIqyREwAVg~caq1ANj-esPKlfroyzVYB-zbeZsD19f6xRvB43hFq~EkB-GnRcDSxx8FvTYfjGD~GP5zQamC2hM60E784WkOiiaD2kn2K8Fy26TKpFMGIEvL-9VltHp7lXBqXUEhvj5aTQ_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=PandoraRecovery.exe

http://gsf-cf.softonic.com/463/8bf/.../file?SD_used=0&channel=WEB&fdh=no&id_file=61540&instance=softonic_es&type=PROGRAM&Expires=1483151981&Signature=I-ZdjN6YHXANC8dq3AEYrBywCgrEEmnWKbAWD6BdRxbJEiyZVN7sEswQOsNWnWQSwGCrRR7xqQYZzXgk1ApdEpC1~VMgOOcYKSIdBYUWP6TkC77LyyPR0bm8mWSJ1~R9R4gmcQ~XFWQJ0DU091bllzJOfV8MYWtAE2DwgZYfcBA_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=PandoraRecovery.exe

http://gsf-cf.softonic.com/463/8bf/.../file?SD_used=0&channel=WEB&fdh=no&id_file=61540&instance=softonic_es&type=PROGRAM&Expires=1472381128&Signature=WpWl3INrylwoslEfcaYDVwlZptxTbSIjr9ywoVSZY7wxUJNzcBDpFW9FFMojmnFe-k6D17NESCJEpLAX4bCEmq~Kcz4q5Y29~-WLX2lnPVPzW2D72~RyFgoxlhomqJRptmw0IVDqxGqvXv6b6Ym579wDhFt09iMOldHJKikPSHU_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=PandoraRecovery.exe

http://gsf-cf.softonic.com/463/8bf/.../file?SD_used=0&channel=WEB&fdh=no&id_file=61540&instance=softonic_es&type=PROGRAM&Expires=1456635552&Signature=UjPqSbF-x1VYt8mpPMQzpI79tSUz5YmZ6weM~Na5v9z2k~BSFqlP5M9e2QW96heesNuzgM4qgOjD5gcbwUHWuQ2XV9opWJ9z9ILdPdO-~hDV-SB-hL~s12JqBR-6uRcUjEnSZjE8Kot3mUa83Os5VpfshBVbB~ixeOwoFVvScVA_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=PandoraRecovery.exe

http://gsf-cf.softonic.com/463/8bf/.../file?SD_used=0&channel=WEB&fdh=no&id_file=61540&instance=softonic_en&type=PROGRAM&Expires=1477826462&Signature=HcFRoprK~UEJuDL8RaLbtn9aowJ~Zo8DXAivayW8WHqiWNU-6lYjYmpApa2fcJNKDtseorfesFwzdb5IxU6YEda3G8S5WbMfChYpZUQI7dVJ5EW3q-5A9dE3VefiVeaeddBxZr2LG9zgXij-maT-KnGElAhscYWCxsRq6JDFxFo_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=PandoraRecovery.exe

http://gsf-cf.softonic.com/463/8bf/.../file?SD_used=0&channel=WEB&fdh=no&id_file=61540&instance=softonic_es&type=PROGRAM&Expires=1482456687&Signature=AW593ethAw3rAw02MSCZn77qCVE3xiIka73dNkD1KkAyQoGk3dpUd2D5MqC5lir8GDJhP58ZUAwDGf33nLJKqnX7NMcMl-FxBJJio~K5k7RoZuG77hJgC-cyPedksQHEZTP9NspPeS-nTmYwmYKG-d9hT9QSQfGC8IjHuYm3ChI_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=PandoraRecovery.exe

http://gsf-cf.softonic.com/463/8bf/.../file?SD_used=0&channel=WEB&fdh=no&id_file=61540&instance=softonic_es&type=PROGRAM&Expires=1474501346&Signature=N~c0CVRYR7pIIY0r9kjPY24HrBXmvNX3O1Ql9h-c8wRCTLMaMWYaQZCpBTcDsrX7hwln2DP8eBvhOt2ycqLQueF~glaN7-mn4fMFf5SuzysWzTRYildFaJ3YYPSS~JDiC2JX8BdXpYQK1bWSayfpR69~HHIz9Bhrn6RUGF3tMFo_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=PandoraRecovery.exe

http://gsf-cf.softonic.com/463/8bf/.../file?SD_used=0&channel=WEB&fdh=no&id_file=61540&instance=softonic_es&type=PROGRAM&Expires=1477896127&Signature=ZNQVLBDOqcwuY3uUAL14zO0LsN6BPU8wxWWzBn6QH5fYy7GVnHD6KsNFzRLkYNP7qsUu0~9FK68OPzMW-yXDSRJdSsal-ZyrdOuVf~VbS8Q6tcmRkZDmRpbsOxLF~e0TJV4gCWBQveWZkeJOF0Iigi9al13lOHw6u4dLPHawVt8_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=PandoraRecovery.exe

http://gsf-cf.softonic.com/463/8bf/.../file?SD_used=0&channel=WEB&fdh=no&id_file=61540&instance=softonic_en&type=PROGRAM&Expires=1478221614&Signature=elE04BtwlMG6mJm2Px45q1EGu44IRp2yuAOgc0NGoB~k5IGYCXaBuvUNKPHdk8CLzTzmGl28FemQTEtsbsD8~N8J96CPCSbgr6JQw17fNlrNtYDwVKiq~adzvw4p4rGHbNLYyxgwmDI9snvNTEmUW1uf9~pK9Eb9~5dTDp8IzDY_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=PandoraRecovery.exe

http://gsf-cf.softonic.com/463/8bf/.../file?SD_used=0&channel=WEB&fdh=no&id_file=61540&instance=softonic_es&type=PROGRAM&Expires=1476375449&Signature=DDkJaIauqNQSYKTgBElL-aeiE06JUE7ysyl-ZGpgr9xCy5DRpkMDhbXv8umBO8tnitpsIA63MIPC~F5CX93sBTBq7wT-E66roOEQVIPx6yfnhmte6~xweZJ-OISmfxB2Z1fWyh9YFuqEYx0FLYo6IVp0OPtVQvP1Cf1VW7mHWT0_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=PandoraRecovery.exe

http://gsf-cf.softonic.com/463/8bf/.../file?SD_used=0&channel=WEB&fdh=no&id_file=61540&instance=softonic_es&type=PROGRAM&Expires=1477886378&Signature=GOntlBUzrSqgg0QWYuEiblToNs4MH4Iri-Mn3KBEnXACzLkIfLSk6FzOkVbTz52Xg4zMU3irMD1UN4qBcv13hGV4JouppHJAjt2YTN9Qx83bMmHkJ8sMOs2XTUFdPTlYo8EAUncyJ9yQrzsOIpkkIGWzDeQY3TJ6KuisQo73jPo_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=PandoraRecovery.exe

http://gsf-cf.softonic.com/463/8bf/.../file?SD_used=0&channel=WEB&fdh=no&id_file=61540&instance=softonic_en&type=PROGRAM&Expires=1473127576&Signature=TLaiEucGuvVtbrNV8A8vP72uMWgAEkfT-3~prGS-u9nPvZk3IbuKpdgjfZd~4r~XXSc8Zu5a9h2uYlMWYWn~UXDzx266DFOACtWzsvUYN-eZyPZ6wMslBfPHKrdTu1vFzsXSAq-CtJp5mXMI0CmflWcuXeLmkYbD6fQIF85Tesk_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=PandoraRecovery.exe

http://gsf-cf.softonic.com/463/8bf/.../file?SD_used=0&channel=WEB&fdh=no&id_file=61540&instance=softonic_es&type=PROGRAM&Expires=1478421788&Signature=YOZRnqryMNcUYR6e5OUJmmiOkfXKNLPNxYCi23WaeSXnSzL8QIY0qAW89db6QLPtTlguH05v6Z9feoBjfGXVdYPcW0OELV7i9N97~mrFOa1kenyYTRtxyIEHsgdgITwDbmoZzdb8E2tU4hRdIfDPX7Rbg7arMmysPo85TAE~NEI_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=PandoraRecovery.exe

http://gsf-cf.softonic.com/463/8bf/.../file?SD_used=0&channel=WEB&fdh=no&id_file=61540&instance=softonic_es&type=PROGRAM&Expires=1471666261&Signature=cnPuteY1G~tA69EllO1fmCl9zTwLJWnAViLK0Cg2kd2a7JCadCZoyr4yAbZDnStjcjgGwFLl-1keZtZrS78VzQvZOh~mV7gVZOGHssHZ8TTvleaKPwi~7N8sHAMeDLUwjqMyYGG2z6J89Fm7iIJek1Qinfc1BrDDAMkOwx9ZKF8_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=PandoraRecovery.exe

http://gsf-cf.softonic.com/463/8bf/.../file?SD_used=0&channel=WEB&fdh=no&id_file=61540&instance=softonic_en&type=PROGRAM&Expires=1472885324&Signature=EViKH~LoXBERl6zWvv85iJDWTQbP7vy2kJY35UEDd8wNIAPVFBH7PqYVlk7xnnIhyQeTrKZHTFATTjmKX~sQVc63BVCbyy-yJd5QZ1wCeMujo3qhSTnLYI6RmR8R7zGG260Dhon~LzcGWv7wLnVXRRUgGu~RvlIDsVX3BE7OVqo_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=PandoraRecovery.exe

http://gsf-cf.softonic.com/463/8bf/.../file?SD_used=0&channel=WEB&fdh=no&id_file=61540&instance=softonic_en&type=PROGRAM&Expires=1466202431&Signature=FMtohBBwHzls1hQN1bcRv~aFaU8g6U-BTLqddi2oW8NLEGwR1VdvOYuLHDWVLx4T9qyBJIR3BSI6krBjFrSU0SSDMZEnB6I3vChifZ7aKfLpZ0uUftg3UgixENWJ8vHz9GoEzo3z9OZlYTTa6a9r6uxrkhlkpO7rVCdBGxhDTQ0_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=PandoraRecovery.exe

http://gsf-cf.softonic.com/463/8bf/.../file?SD_used=0&channel=WEB&fdh=no&id_file=61540&instance=softonic_en&type=PROGRAM&Expires=1472703166&Signature=bKgkuBPCmuHYOYg9nr0xxISzUp27JcaKIVfXx0ETxtV3aV7gyqll3oNut7x5TTRnOXMD~eo-cdmc1xU4TWhgCOXulgzRa0tLPhJxHCmIbiIL66aZAjVlPft7HzI2~LuBYGbHqwOOeAT8Iyte7t3WSyzDFU2LDpyXCSZUqAtuBj0_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=PandoraRecovery.exe

http://www.lo4d.com/get-file/pandora-recovery/.../

http://gsf-cf.softonic.com/463/8bf/.../file?SD_used=0&channel=WEB&fdh=no&id_file=61540&instance=softonic_br&type=PROGRAM&Expires=1480928050&Signature=aAZYfsXVbcIzoLRwoJROUsSPwLF66kKvFHfvHqN6gRarirV~Aaf9VatwEqTHpDIsgEOLHh7i2RiuDC2GwSK9GFx2DRP~fjUW8HD9x~OghXuah9IKCVRw1vsdXfXeV9eFDY5RzITFpiWG6agGVgWV5E8Tul66aNhf-VrHRFuuNRE_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=PandoraRecovery.exe

http://gsf-cf.softonic.com/463/8bf/.../file?SD_used=0&channel=WEB&fdh=no&id_file=61540&instance=softonic_es&type=PROGRAM&Expires=1466846589&Signature=ARC2dxokOqJHYh96i5u6TZ7V3yb10NrVLPBdrY7tXNOCPC7xQ76ackzLheRdEYiRik7OAax6wJbytKzpHUpTf0-leiyPDjI4DwxSDksjaa~SxigdBL~SUmor4UvyvzGErcwXnw5Cac6szD-cKND2ODg75DUocNyNA0BCtvMJWQk_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=PandoraRecovery.exe

http://gsf-cf.softonic.com/463/8bf/.../file?SD_used=0&channel=WEB&fdh=no&id_file=61540&instance=softonic_es&type=PROGRAM&Expires=1423371999&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=A6mEgEu3eJabdzzsw7CKRBB68pAUY-4LDrpZ6cAM6ZyyEpv~g2zI55W344PcXf3JGHQKUVVE0cgtvV6YKNBU-t0u~UP6EcX-E0besO6T8h5sZf5qE~jstLbvdDfneQ9QiXESYKbylAKLdow8EP9hQawKbwBZAxzaYdR1yROXtuY_&filename=PandoraRecovery.exe

http://gsf-cf.softonic.com/463/8bf/.../file?SD_used=0&channel=WEB&fdh=no&id_file=61540&instance=softonic_br&type=PROGRAM&Expires=1450146252&Signature=idUSeEoEPlZCySYYv4kRvnXCEVd8tfgJprtwyp8mz6txZs4yvbR6LEmky9aLzgA9-8G5sP54omo~beTWIDP2oogSZI7-xa-bMYWprTco~C8e8npQwsRylBzghRmOiBU80hBZfn~T9Dq~6Ejw8xrZcOBLItmlT1Fby0iBVAUK5GM_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=PandoraRecovery.exe

http://gsf-cf.softonic.com/463/8bf/.../file?SD_used=0&channel=WEB&fdh=no&id_file=61540&instance=softonic_es&type=PROGRAM&Expires=1427167577&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=fbTddMMcKZZsH4OkIzTl95D4tnsEFDBbNizXsBziM9~BCJZcGxdnGGc5aY412DVi5jykuQMeJDgXEvoil~oKHJR3DRDoQUgRo7PODkmdLObU9KBGIQeaKp5YIkA2nHKiL3vWS63CLLhfvfOYHMGwvIZDEEnr2jgDg0wek6dtsG4_&filename=PandoraRecovery.exe

http://gsf-cf.softonic.com/463/8bf/.../file?SD_used=0&channel=WEB&fdh=no&id_file=61540&instance=softonic_es&type=PROGRAM&Expires=1477982227&Signature=VXjLzT7zP-1naMmGMBe1vmLCML3iQIDLYOIJuES2E8qpEI3H17Ab00IXtoXox90fxAYUip3-sb0PSweVqPaKTwzw8JgQ9NPCRZmFQa0NOk5ovmcs8yQo6iYCpOCoKtOdhnIUKbzl~RbxBxxf4LCs91QIFoApYnAmpevw7-laN1E_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=PandoraRecovery.exe

http://gsf-cf.softonic.com/463/8bf/.../file?SD_used=0&channel=WEB&fdh=no&id_file=61540&instance=softonic_es&type=PROGRAM&Expires=1476234961&Signature=RWF5qgexbCgZKyXOlxLIHA9AMs1vh-~htwRp54gPHApCx7qlDxI0FOEbgTE8GoTVty1UOjl9Cfgjysc3VkCBLk-Af~fyjkfIl53icA3V9qruMV5nVQ-1zAnFmRt2BGvjwWVHvhBOJAqkFh71maOKkfbg9Bjacnu9AbYWM9uAkew_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=PandoraRecovery.exe

http://gsf-cf.softonic.com/463/8bf/.../file?SD_used=0&channel=WEB&fdh=no&id_file=61540&instance=softonic_es&type=PROGRAM&Expires=1467200669&Signature=KAOdV0qMm~cottVPhR90e6HYbqLAyE8ORP5uOf-9iaUKGXEMTv8OL1AC9bDvdrz04IMVPOWGbtV46I41nXiECtDUOMFIHIelgdK1XaQ1Qj1jdUGjZ~tTS01PVMp4~EQk3lfhYh6WKaulVKrInCI1pJp5jF2kqAdp5G~x0cdmzuE_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=PandoraRecovery.exe

http://www.aaafarmapps.com/c?x=xs1g7iKLoQF6zn6STMD14jIjBesdrSI5A8hHA9kbOQQ=&c=9H8zmMkbYEbKLHJctn7NeDKjbhTALXgsXNtyxNau9FGoW/9TJjuxYs8SEEo7TfHmCdO3xBnyu02toT narttTNEN4dDrrw9FDW0VH NHd7XfV9xY4bUpjAV5b1EC8xs9U1CysyLQJZ b7955wjdCvg==&fallback_url=http://storage.dobreprogramy.pl/.../PandoraRecovery2.1.1Setup.exe&downloadAs=Pandora-Recovery-18186-dp.exe#

http://gsf-cf.softonic.com/463/8bf/.../file?SD_used=0&channel=WEB&fdh=no&id_file=61540&instance=softonic_es&type=PROGRAM&Expires=1480508874&Signature=DxXkyFETu9JIHxdkuxF5U~3s1YMAniBhehvHFnTbvpw7rqnuQ7WlLFTeGL~YjDZlBKhsN9m2QhRqqmGxjXxMyRp95hmweJ3LnFG0w8hBGdCvbD2Vo4pBOVr0E~~vPh884NWGXcHD3eSctnnIjAAkcVY2lqW1r0pGIivxxff06VU_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=PandoraRecovery.exe

Latest 30 of 143 download URLs

Scan pandorarecovery2.1.1setup.exe - Powered by Reason Core Security