windows-data-recovery.exe

Disk Doctors Windows Data Recovery

Disk Doctor Labs Inc

The program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
Publisher:
Disk Doctor Labs, Inc.   (signed by Disk Doctor Labs Inc)

Product:
Disk Doctors Windows Data Recovery

Description:
Data Recovery Software

Version:
1.0.0.6

MD5:
5cdc8fd300eb85a8942b50336bd04b65

SHA-1:
878837368ee0c9d0409c663a9ab84ea9afd09dc1

SHA-256:
78ca04b456027ba1987bd73f7bb81a38662f7419f2092ad08fb9107eae7c33e3

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/18/2024 4:27:56 PM UTC  (today)

File size:
9.4 MB (9,834,568 bytes)

Product version:
1.0.0.6

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\windows-data-recovery.exe

Digital Signature
Authority:
The USERTRUST Network

Valid from:
5/26/2009 3:00:00 AM

Valid to:
5/27/2011 2:59:59 AM

Subject:
CN=Disk Doctor Labs Inc, OU=Software Division, O=Disk Doctor Labs Inc, STREET=5555 Oakbrook Parkway, STREET=Suite 115, L=Norcross, S=GA, PostalCode=30093, C=US

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
00EFB9A9EB217617D28D3F6A79C770FEE7

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
196608:vzxlnXaKOrskqJxGbC9Y1Iy1jWcbg/tHI2QEu5+gAGy9g:FlnXaxskUoe+yyVbgLNgAGV

Entry address:
0x9A94

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 32, 96, FF, FF, E8, 39, A8, FF, FF, E8, 64, CA, FF, FF, E8, AB, CA, FF, FF, E8, 0E, F3, FF, FF, E8, 75, F4, FF, FF, 33, C0, 55, 68, 47, A1, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 10, A1, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 9B, FE, FF, FF, E8, 02, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 94, D0, FF, FF, 8B, 55, F0, B8, E4, CD, 40, 00, E8, E3, 96, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, E4, CD, 40, 00, B2, 01, B8...
 
[+]

Entropy:
7.9997

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
36.5 KB (37,376 bytes)

The file windows-data-recovery.exe has been seen being distributed by the following 3 URLs.

http://gsf-cf.softonic.com/878/837/.../file?SD_used=0&channel=WEB&fdh=no&id_file=73199&instance=softonic_fr&type=PROGRAM&Expires=1474321631&Signature=Frb4y6~HvJuqQU7Jun-bDEaRNOdh~pT5wFgd9lyUbIU7j-buAcE2PqB5gNF7xblS~JL2gqqt~F9CvdeCJyUiQQz6eFRVoJQHNc98hwOTc6kYq~K9JKcNn~SogYkAdz7FVPj1ZyYOTM9i2aH5lXdgCfd80Mow9Kp-7zTfbizkqgM_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=windows-data-recovery-2.0.1.exe

Scan windows-data-recovery.exe - Powered by Reason Core Security