filerecovery-demo.exe

Active@ File Recovery

LSoft Technologies Inc

The program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from dw.uptodown.com and multiple other hosts.
Publisher:
LSoft Technologies Inc   (signed by LSoft Technologies Inc)

Product:
Active@ File Recovery

Description:
Active@ File Recovery restores deleted files & damaged disks

Version:
13.1.1.0

MD5:
e66d7d7c6525ec5df1fb4f61b45bde51

SHA-1:
178f1f048dacf1ab345b3f4c72e7ad4d4d4cab27

SHA-256:
5746816824d5f7453e43275febac99a89b393ab9db13a5582bb659314de39b54

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/23/2024 6:31:03 PM UTC  (today)

File size:
14.6 MB (15,264,584 bytes)

Product version:
13

Copyright:
1999-2014 © LSoft Technologies Inc. All rights reserved.

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\filerecovery-demo.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/16/2013 2:00:00 AM

Valid to:
7/16/2015 1:59:59 AM

Subject:
CN=LSoft Technologies Inc, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=LSoft Technologies Inc, L=Mississauga, S=Ontario, C=CA

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
08D2CA5078B165B7C8ACB225FFC7B80D

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
393216:8eYU2umKGWO+B4HAh+9jqUq8FcMCb3xT7W:8eYU2ujVOPHfqYcMCb0

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, BF, A9, FF, FF, E8, 5E, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file filerecovery-demo.exe has been seen being distributed by the following 29 URLs.

https://dw.uptodown.com/dwn/Fci5d6EpfFQ40r-ozLsbmi3z2yimOnW_jr91tRQF08aJU8OxcFZoOcOgs-cWTtKoNckpGt912XUnqP-ei1JF_SY0ba31ohn7AQOVpg9FJQKXs-T5wF1FR1XosXXlkFf8/PIsEuOfbS1SOLUfH8bmSWeYU859ChVPcep71npujiFSsseLwgK1CDym61TAnf1YqeQu8COIfehQ3YvZ1YAHP2o3-TcRcCKtCHCvtTi16LeFiaoWXKf7ewJ245sBAL11m/vtT_YaONj07nbxlBjXDiN09Jh3Z6ZPvD9uvRimRcSo7UMvPJTQ2-dPlzWHRCVTXNyDzzyXT1peOuVOC5HdHuiWMSTPmekYJTAU62Sh8xNf3c4M3teqzJLUSlZ8iqcbZY/.../

https://dw.uptodown.com/dwn/JZaDA4bGPFZP2Yr_QFaEb_vYT3KzmM1CeKYvvbPMiv8S4Sq903ZANAm4vF934JcyDv2H71s__JH0ctVsJWbPMFb1z2ZcjxX1tbqd5xwcJdFshp7swlVWdV0hUMliquNK/KtkFykJL3NWpk8X2u5dvFNRx0p_Oz_qJq_MiHMUS2M_OqPbTZ50_-AeAnhsXdyBJFnxeWxImnUB5doDjXV7gt7XjLjvlNsLnrVuWcqySGGMRcZyNAPHxunfB6oUoAgH_/tRU_kx2qiN2NO4o_Vjyhg_SXQHRqnsrps39vuAA2eACQrqUBmDS0GfwjY3t4sklxZVkK8WMDzq9qJ7ccds7BXkuemNcEMWrKWa8xCpnpIss80PNIW53yCtaeozv6NBk6/.../

https://dw.uptodown.com/dwn/uZQTwgrObvg0tewg9uSWI6okLW0RAGCCwfvQ8o8Lp6nEs43HgYytDmehGGmUwF2muzfXIWD6QekZPzobNOj1ITpxMynLIEwJ_q-LeERzRfDYzsyQtYvOwVtFykcaF8wF/kGy_pIIqNLNHtsRX-kXt8XZmdYCSTSJ9_VaTNKnrobCqzZVgEhGRC6YwjGCFAEAJUGyRG5CaXsXIq34L340MTaric145ZPqpiWar6OnUBfCrqUPteqlF5oP2tDxun4y3/QmqfG0hgOCXe0Bbkp68XUcN4kNzcrinLJsRAeU3ffHQ9KzMqqCxxc-9hraxxXjp1-YpxLcizwkKXF56prrNDJfEA4GLCWrAk3AN89NiV8OQGqMbOyoBAPZFohXCy497o/.../

https://dw.uptodown.com/dwn/rdCcJK0ifpoV8CTTVHvOxv-85O_gvDcKHS8Bch0vrCfpdioR0_PPklg4t_sBuTiMFSsBN8QjSVtamVRn4SXIMgb2m8HNlKEZsWtjy3-17BtR0Nh7cjCjFmVibbU2_VeM/4uGlL7KSyFgtGR2TY-nmqG8Jp85vlYY29gnQDQYk-BEqNPhx-8tSIap8Su1W2-57ezmgybwGlcpeyOjExoWCc6Zaaq1SBnRqKCsSy2S1E8CKHxrVt5ckMQ5bqlcSp0dx/3lvBxm4nZ34-gnL_WapN3215kbJ8rrrZAOYhBWlJk95kNzFzb_WZkD2NGzs7XIleKsWoM5pNewtUQPNiZ2OsyikEFVkdq6yNxFAx-i0SR-zauqaJ_jlAZWhOsUAYVzgP/.../

https://dw.uptodown.com/dwn/SxmWnnkbFyGdY-NgLWgbAmLBTuZPy0PXACrkqMMmEHQHsNQhYFRJEP9GWIgZClqMEgf54FQx7ztz_BsdtGuiEPf0DzXfWJoKT0IX-866tSDh4Wh4R09DaE0H6gHlaQiy/6hn7RHlQVRA5W9-3aphl75ttzqS2nB5PBm5TQ81yCoLHYN4eK8bavfj565cjkGfmIZIcTKRmwDobRlvzl3AeZdGGWjzJxCKRIGIyrTu2GzZF1MqNZ4qWkcQavkE1Qotx/dDK8rzNI6MBX3Zh0tWvSsS__Q_R9oecN-EKi70ndZfkxJPmlo7N3RhsOY0eXYHCPpjLgMtgbp_CxNpORIW9iAe8riucXTBsDGtUZPLENoMyTRUGa_UHYQeCPJ3VSjcnx/.../

https://dw.uptodown.com/dwn/D3iRXegUTboEwTiBHBbE4Tfga9cWAKhCSHgUV6O1_Fdx-nbRXYiw1JPbF-3ZyLNZ35yVOwKzLtp57xSkBx0Ajdy3d6eOGNAJxLxun1oACNbUAjlZrbtmvm3OtGILuIAL/vAwP3Sq4KA_aCvsQaT0zRpctumUzvSVdLRC-ov-QW6nVkwQ8nYVpizzFqpZt4lbvbx2h28G43S6FKO3V7_5rNaJVx397tcH1BBKJ54WCfcSVPMqTwkr_FZIBGjakWtAr/jgpvzWujOtGxKnlXQY_WDcR_sESrXz6yGsAS6fKFmp-BF73fItQQvBcHi9Q-wtYYc1pmA_lZj0JST2pzhoCXcTpv4UZzE9meC6dIpr4fRdwTGuGul0QI9JmS_x2UOoEZ/.../

https://dw.uptodown.com/dwn/gDU6dTxAiKWOw0dJMVi2OvGmUnEL4cohxEpEdWIcjRuU1k06NAZNzKKE2-0sjolcZ8Hipw9HYhyPMWfbbUsww7tPkXMa43n1DKonXNTMzr3gsAf--ny6KDh7R7vRnu9i/4VXQEvHN2rIcNRXjqdQUR8HjdL86tIBdy9mL9AP9tK5XzQET8cyU5vGa0nHNqaSC7GJWD0mLpUC9oVE5ELZcRreZRZn0zc3LNmUxaan0qiT8pJTflw66BGWlwZDtMzR7/ciyLPDxGHcmg8_FINcDGlbnLXC5tkktmEWouFd1Ui3dM5sbiwivwRA22icACWlsL6oaXUm0k1rLYtEa7KVe-uLjQfpdHwlIk2ddf0eb0egKDJkUC_8UAfYZ68ycJhfdw/.../

https://dw.uptodown.com/dwn/LKBk3yMgQNKFu6x08qveYTR8o3seFAn10EIxXI1UdnZCPbdLkQng5O-R7X2wMewOtmypfx3fQndGTAHrF5R5tbVUwRoyQ6bkEXBnasHoDwHuOh0shN2ZsyxZY5gKmVQv/dn02u-hcMvZ8BAIaod-GURnCAXPcdEla7Ki9aXgJAV6yuBwht7ZzFIgIsuD38v2h6IrYbYaZHtKNqM93CDkqRdxGJ6Q_NLvu7liGrx-4K9qv9Px8rHUi5UCS414dj9GP/tnGXO9fnEhZZ3VyqUh8veIjfr7kS6TjSyfhTe61qmT2n_wUczqm3AUsRAwDmROAQeE9xanW39hfYh7kSHmPRogqu4TVrFUb7XBziVHWGP91hpj-AUeBAUc1v7HZRKYKD/.../

http://www.file-recovery.net/.../filerecovery-demo.exe

https://dw.uptodown.com/dwn/T3rxXFA5JPdUTZ_IJnB98Oe6ic659I6snGH2toH9ds6g_KcPW-CN6TdjS9dsuGmt2a5vAGFxgmzNbJ84PN3d4MnMoW5VTLuHdnLZT2f6bR_oOaH-u9xj-wOpbgDmBBu8/JBIr4OqvKpjvUzoBT3VPjwbYgFDyvF2iZNwgsjsEKsMZQig2vQi1lwoooxOysFwIC7Z2IkvPqEam0-X7QK8KiH9z5HBz6sqcqc8ntVUvv0K47AcF3Eh3TZMx354Vmj3k/OsfkJsImikgYbwg22zJYKHH0jh8KVuNVSEaaL8vexQyYx5k7vML3eSZ31yOf5DZb8M5N0fMc8LLN8tSs2ry4xfxImCsgSnoO9jiL11XXPxAvf8Z1YGJxZf02vi11yYAf/.../

https://dw.uptodown.com/dwn/y0RSAtAyDNyf_YLvaVJmTPNZh2fVg0asWxL2S4j3OOE5RVg8Cq-qcGmc3GWnqoJDzC6aK-3GnRAaAN02W-Nkbk9XZ9mGO3DDXLFwQZV0RzDdWiMmr5_OHezMvswE6Chg/J1WY8RjG8L9mUaji7FEuxyIlhfbZhiHHm7eYrHoSXmZu3vP-MfxZnw1hX0nZfFmuksRF0mlz4KpxGgNVW21Pd-XyVdGvwmXgfLC-lQt9lqE3ON9CKLu65SMr29CIp6fX/yH-L262REGsg_A5rpKDD_V3yY4FiedkvrQvLTgx75wa9zZdBaH1nTml7tACZQ7hGIMUPf1Ox9iUyf0MwbCky09m738L6_PglGun1bJQ1NExklIOog2JdIhyxsc_qQPcM/.../

http://dw.uptodown.com/dwn/UdS_K9dJJfHwU5rR-lwVgdUmXlYGSuQPb-h1RLwKihEG9chpnCex-eV0qWIQjyMGc47s5JNxfGXmNuzAK47X9d4Uxl9sk_rJDeZAUf1YEU8XEspJ1hzl2lBmmUHtmTnb/Fu7YVvB5h61dXPzQtnvvJMWE-VnI77YGVckn3RIeil2qHz7tlt_oD0DhaDCm2Nt1PFRs-J9FD8ehAeyh_nJQRgAZ1Rp-TYpoEOo-RceoUId_YaH3B5MOb8J3J39Lj2JZ/XDovDTtbhmQuP43UjZMm7WYOOGRyFKR1AoFsf9HtxOOYnURHATohjn23cQFtOHRXLiIAXl8K5CtcQyPJ9HoJKOTuRARHDoL8eSLOhHQ0VaqkJA6Cxu-sG8Iz5GdnrXcv/.../

https://dw.uptodown.com/dwn/PVZDfDHy0t1iYn2wW6QPO4RY9wFqV54ltFR5lV3p9nsKFJMVp8fzmDhVQyxFj9hw-eUKUBhwb-fV-w1bC3ckl3ZxdzllmbrcomvQC2mTM1FEW-T0EvI3uKP_mRoox6TJ/kSbhygMba1CnEtwf-gW934rFO4iLWx6jkDRjU37XxMNhdAUjGM1vjY_0JoTTCQ7SiDzCE628m4Z_mKoqAn-_Rk-dNfsNIf-i5e4n4RbleKiTpaEpnhVK0ZgKsbuG7Qwx/SpZp6LG2USrTGOSMcK_m9LuTp6xsdmTcOJ7ePb0XCmVQoV0EWfHFEfywKRgB8Ho8tvkzQ115FtHOo2iBaV8UE3qKA28t1ylJLFGN_h2IqNjDQTlF7Yv3NbzHx3phhxw4/.../

http://dw.br.uptodown.com/dl/1440943328/.../active-file-recovery-13-1-1-en-win.exe

https://dw.uptodown.com/dwn/D9uKwQgeNHJFZRkGF1BsZlTbKNPm47ATPoCmnqhE-ieTsX1sk3z-HyDyKMbwHZOmxXt8xAak2HeqZSrEmQz_Okkp4kzlZthpZRnYRWz0Zn7V2hSHFk8ooRvEYPZB8yMA/5JF0fnvxv6kCjTtjfiQkhqdil4SXjURGSNZvFuwT0OHaXmwJWJwOk3LdVo6eKE5T8BGtJltMrH2HObUmJPI9JsyyBCBlyQuqSUTiReOjPKKxGmP0bKVviaCV_f2XXtPx/YFaQHbWD0B3fSF5_CPVyPrEr89_ZHaAPNdaelO7d2iGh8KRHCZsAWv_FYmgOP2z_veiIrL4TGpd31fIs14L2YNAxLU548BV1xiHfGyS9y5aWX1ss7LNstn_KEcaxUUvC/.../

https://dw.uptodown.com/dwn/3yjOzKo7q_XThmV3JW3wgGB9FmnwYj1mEwwVNK9Q9loU-PectUFNgViPpeVASa78ixxNcPRs1MpvNJ7ayBq8dTJmahyof6MYJtZmrae5ZEU_zYJPuTv2_svKdo5qnycA/kInw0tTtwoVlD5TedtisRQvbi125tXBqoYs5yd9OeSnG6U3LjmtbjWgGAMbnC5AwL750MYoDrtwbPKg7NeBvPIeNQmtpTVarJxpAPyvXOyt9dTOwq5lE_QMaV4z5cCoU/JXb_hS9CdUEdMkWMRsAE_a61jOfUJDQLCzbi7qXJbprJ0RgRlhQeIepbItrQqaXZsPcyPz00dtF5NdJ0UMJGY0UzHOqdZOE2wxvlQtQQ-1E8iqkB0GJWflB-4sxE3s5k/.../

http://dw.uptodown.com/dwn/qXKeWAPAaf0S626iskoY3n5vhTHFDO3p_dO7JzTUNZNrEo1F777juqqNZ7lnOKzu2lVFQZ-AtxDE-FHSR4JRac36O6KX49FOh8PA3vCFm1p4H41OQtC8ZBujE0lqo5uy/2X5bl969c8epdYmgwpiOHHWvHLRs1Qyts56o-7gnKPHWknZaT-2VrTJ1uAi3WBovn2IlPl6ASRony1t_e8eshkZStbjU_ySsKO6JpGeLiFnjtvMh1zztF2kz1LrOH0EY/27uvq8_SDG2TVeETIybRTRi5lKu7P8XfucAdZrF3QHbieVUflxUfORTejXSgMjkI0paQPKavD_7V5gPSYp14pAQH5emb5mON-mnJ6gRKw3id23oqi21pvfOLYoymaYtE/.../

Scan filerecovery-demo.exe - Powered by Reason Core Security