UdServe.exe

Undelete 10

CONDUSIV TECHNOLOGIES

It runs as a separate (within the context of its own process) windows Service named “Undelete”.
Publisher:
CONDUSIV TECHNOLOGIES  (signed and verified)

Product:
Undelete® 10

Description:
UndeleteService

Version:
7.0.205.0

MD5:
ec8a63cc2ecccb794ef52bae90e3f02c

SHA-1:
c51accbe9ecaea67f1e27d3542df2d1ec5dc1b34

SHA-256:
4940e48ee8b3d6ade0cb684a6f22147dca8f6c25df679f15ecd630577c36d517

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 10:42:42 PM UTC  (today)

File size:
1 MB (1,078,544 bytes)

Product version:
7.0.205.0

Copyright:
Copyright © 1997 - 2013

Original file name:
UdServe.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\condusiv technologies\undelete\udserve.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/12/2013 9:00:00 PM

Valid to:
4/4/2014 8:59:59 PM

Subject:
CN=CONDUSIV TECHNOLOGIES, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=CONDUSIV TECHNOLOGIES, L=Burbank, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
14FEE2983B54274D1B49694F7FB044A9

File PE Metadata
Compilation timestamp:
6/11/2013 9:28:14 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:duRLknwYvs9RYgwUJ7WmU/6YvCu9uvJie+RFWqcx:duNxwm+66CIM/bn

Entry address:
0x6F30C

Entry point:
E8, 1D, 78, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 50, 0B, 4A, 00, 89, 0D, 4C, 0B, 4A, 00, 89, 15, 48, 0B, 4A, 00, 89, 1D, 44, 0B, 4A, 00, 89, 35, 40, 0B, 4A, 00, 89, 3D, 3C, 0B, 4A, 00, 66, 8C, 15, 68, 0B, 4A, 00, 66, 8C, 0D, 5C, 0B, 4A, 00, 66, 8C, 1D, 38, 0B, 4A, 00, 66, 8C, 05, 34, 0B, 4A, 00, 66, 8C, 25, 30, 0B, 4A, 00, 66, 8C, 2D, 2C, 0B, 4A, 00, 9C, 8F, 05, 60, 0B, 4A, 00, 8B, 45, 00, A3, 54, 0B, 4A, 00, 8B, 45, 04, A3, 58, 0B, 4A, 00, 8D, 45, 08, A3, 64, 0B, 4A...
 
[+]

Code size:
544.5 KB (557,568 bytes)

Service
Display name:
Undelete

Description:
Saves and restores deleted files using the Recovery Bin. Part of Undelete, a Condusiv Technologies product.

Type:
Win32OwnProcess


Scan UdServe.exe - Powered by Reason Core Security