Recovery.exe

EzBackup Recovery Program

Data Protection Solutions

This is part of an adware program designed to inject advertising in the web browser (banners, text-links) as well as modify the normal behavior of the browser. Part of the Injekt brand of unwanted programs. The application Recovery.exe by Data Protection Solutions has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Data Protection Solution (Arco)  (signed by Data Protection Solutions)

Product:
EzBackup Recovery Program

Version:
2.00.0008

MD5:
c3de8d96102b816c2b5a704154d6f2f2

SHA-1:
c35454eab491e539274fd23eea9b642d58c2d3ea

SHA-256:
293e592f0c6a4bad771334857b3f4c0e40f636221ade61f205198f2e3c12c937

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
8/2/2025 11:35:02 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Injekt.DataProt (M)
16.5.24.19

File size:
409.9 KB (419,720 bytes)

Product version:
2.00.0008

Copyright:
Copyright 2000-2010

Trademarks:
EzBackup

Original file name:
Recovery.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\dps\ezbackup 5.0\restore\recovery.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/13/2011 8:00:00 AM

Valid to:
6/2/2012 7:59:59 AM

Subject:
CN=Data Protection Solutions, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Data Protection Solutions, L=Hollywood, S=Florida, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
44EB7C831EAB6F108628776BD16D247B

File PE Metadata
Compilation timestamp:
1/12/2011 2:58:13 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:yP/yBV/1GY0l+Iuw41OjN3WrL79SnhNNpsx6:ynyBPfw4sVWRSnhNPsx6

Entry address:
0x202C

Entry point:
68, 78, 21, 40, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 16, 5D, 15, 5D, 63, FD, 23, 45, 9B, 0A, FA, 6A, ED, CC, 3D, 32, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 2D, 43, 30, 30, 30, 2D, 52, 65, 63, 6F, 76, 65, 72, 79, 00, 30, 34, 36, 7D, 23, 32, 2E, 00, 00, 00, 00, 01, 00, 04, 00, 40, 63, 40, 00, 00, 00, 00, 00, FF, FF, FF, FF, FF, FF, FF, FF, 00, 00, 00, 00, 54, 64, 40, 00, F4, 47, 46, 00, 00, 00, 00, 00, 30, C0, 24, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.0185

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
392 KB (401,408 bytes)

Remove Recovery.exe - Powered by Reason Core Security