DiskRec.exe

Disk Recoup

QueTek Consulting Corporation

Publisher:
QueTek Consulting Corporation  (signed and verified)

Product:
Disk Recoup(TM)

Description:
Disk copy utility for faulty hard drives

Version:
2, 1, 0, 1

MD5:
bc55e6e52725060b0c4189b177e23d63

SHA-1:
efebef332f26defc4c68dc35e31f8a08116e15ee

SHA-256:
27c0b8f68f6bdaf0a17fc17521dbe30a4ccf1dc5af855d6d7bb47fec8ff9a86d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2024 9:33:55 PM UTC  (today)

File size:
901.5 KB (923,152 bytes)

Product version:
2, 1, 0, 1

Copyright:
Copyright (C) 2005-2008

Original file name:
DiskRec.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\portable disk recoup\diskrec.exe

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
8/7/2008 3:00:00 AM

Valid to:
11/2/2009 1:59:59 AM

Subject:
CN=QueTek Consulting Corporation, OU=SALES, O=QueTek Consulting Corporation, L=Houston, S=Texas, C=US

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
5CC66BBBD3073547E341EC1D58690EDE

File PE Metadata
Compilation timestamp:
10/22/2008 11:42:39 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
12288:xRWMub+VKuZq4Cd7z4ZQHJz+wXIaOvyPvcfnUMaFDMOX2lB7KuQa:Drub+Vd44u7gFwXIaIyX6nbeMOGb+9a

Entry address:
0x4776E

Entry point:
E8, F5, 8F, 00, 00, E9, 17, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, 80, F9, 40, 73, 16, 80, F9, 20, 73, 06, 0F, AD, D0, D3, FA, C3, 8B, C2, C1, FA, 1F, 80, E1, 1F, D3, F8, C3, C1, FA, 1F, 8B, C2, C3, 6A, 0C, 68, 60, 1D, 48, 00, E8, 2B, 59, 00, 00, 83, 65, E4, 00, 8B, 75, 08, 3B, 35, 34, D3, 48, 00, 77, 22, 6A, 04, E8, AF, 91, 00, 00, 59, 83, 65, FC, 00, 56, E8, F1, 99, 00, 00, 59, 89, 45, E4, C7, 45, FC, FE, FF, FF, FF, E8, 09, 00, 00, 00, 8B, 45, E4, E8, 37, 59, 00, 00, C3, 6A, 04, E8, AC, 90, 00, 00...
 
[+]

Entropy:
6.7457

Code size:
416 KB (425,984 bytes)

Scan DiskRec.exe - Powered by Reason Core Security