edpr_server.exe

Elcomsoft Distributed Password Recovery

ElcomSoft

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘ElcomSoft DPR Server’.
Publisher:
Elcomsoft Co. Ltd.  (signed by ElcomSoft)

Product:
Elcomsoft Distributed Password Recovery

Description:
Elcomsoft Distributed Password Recovery Server

Version:
2.99.412

MD5:
562bd4d3385df2bb3bb0a8e3f5ab435c

SHA-1:
42b4a863434eea9fecd673bcdb9edf2e59309efd

SHA-256:
ace0c95d03b43218f04777e095f49af530281a8b2345ddc90c28fbd2ac4c4c18

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
1/13/2025 12:11:50 AM UTC  (today)

File size:
454.2 KB (465,064 bytes)

Product version:
2.99.412

Copyright:
Copyright (C) 2002-2010 Elcomsoft Co. Ltd.

Trademarks:
Elcomsoft is a registered trademark of Elcomsoft Co. Ltd.

Original file name:
edpr_server.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\elcomsoft password recovery\distributed password recovery\edpr_server.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
9/26/2012 5:45:00 AM

Valid to:
9/27/2015 5:44:59 AM

Subject:
CN=ElcomSoft, O=ElcomSoft, STREET="Bolshaya Serpuhovskaya"" Street, 44, OF.19", L=Moscow, S=N/A, PostalCode=115093, C=RU

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
1748F43D845D4B8E655BA399F2F7EF9F

File PE Metadata
Compilation timestamp:
6/18/2013 2:16:44 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0xAD633BB

Entry point:
E8, 84, EB, FF, FF, 42, B3, 35, E5, 74, D4, A2, D0, 48, BF, D3, 50, A9, 14, 2D, CC, B1, 2C, 45, D0, 29, 8C, A5, 0C, 65, FC, 15, 9C, CB, 1A, 33, AA, BE, 4B, 6F, 2B, AE, 6D, 33, BB, 20, 1D, C3, F6, 0A, 83, 74, CF, 8C, 38, F7, A4, 65, D1, 50, 88, 3D, 95, 46, CB, 24, B7, 6C, 88, 19, 96, 92, 5A, 84, B1, B5, A7, FD, DD, 52, C5, FC, 56, 62, CB, A1, 28, AA, 4B, 1E, CC, D8, 24, 97, 20, A2, 8A, FD, D3, EF, 4B, A2, E0, 51, D6, 0F, D8, A9, C7, 1A, 11, 01, BF, E0, 16, DF, E7, 54, 8C, 9B, 74, C7, EB, EF, 12, 0A, 93, 0E...
 
[+]

Entropy:
7.8520  (probably packed)

Code size:
301 KB (308,224 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
ElcomSoft DPR Server

Command:
C:\Program Files\elcomsoft password recovery\distributed password recovery\edpr_server.exe


Scan edpr_server.exe - Powered by Reason Core Security