freehiqrec.exe

The program is a setup application that uses the WinZip SFX installer. The file has been seen being downloaded from www.roemersoftware.com and multiple other hosts.
MD5:
fd3696d1f5d97686b7da30651ef6c2bc

SHA-1:
fd9bd7a56eae3fc6549a691ab8d32271c5fb13b7

SHA-256:
c812ec67afbbbd7749d7a2ac3153e22d1c70211f9ddafb11b374e2531bd88cef

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 6:43:11 PM UTC  (today)

File size:
3.2 MB (3,303,936 bytes)

File type:
Executable application (Win32 EXE)

Installer:
WinZip SFX

Common path:
C:\users\{user}\downloads\downloads\freehiqrec.exe

File PE Metadata
Compilation timestamp:
1/9/2001 7:09:05 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.10

CTPH (ssdeep):
49152:vrCTbLGrClPp6aBWBU3Olf1nFW3Jah4xmkapz7yEWsF5eI/RG9Hrbk5n2:G/W0B6eKU3+1o5G4aZn7RGpr4t

Entry address:
0x3F8F

Entry point:
53, FF, 15, 4C, 70, 40, 00, B3, 22, 38, 18, 74, 03, 80, C3, FE, 8A, 48, 01, 40, 33, D2, 3A, CA, 74, 0A, 3A, CB, 74, 06, 8A, 48, 01, 40, EB, F2, 38, 10, 74, 01, 40, 52, 50, 52, 52, FF, 15, 50, 70, 40, 00, 50, E8, 9E, F3, FF, FF, 50, FF, 15, 54, 70, 40, 00, 5B, C3, 8B, 44, 24, 04, 8B, 40, 3C, 05, F8, 00, 00, 00, C3, 55, 8B, EC, 51, A1, 88, 94, 40, 00, 83, 0D, 00, 93, 40, 00, FF, 56, 33, F6, 39, 35, 40, 8E, 40, 00, 89, 35, 34, 94, 40, 00, 89, 35, 84, 94, 40, 00, A3, 24, 97, 40, 00, 75, 05, E8, 9D, D2, FF, FF...
 
[+]

Entropy:
7.9992

Packer / compiler:
WinZip, 0x32-bit SFX v8.x module

Code size:
21.5 KB (22,016 bytes)

The file freehiqrec.exe has been discovered within the following program.

FREE Hi-Q Recorder 1.92  by Rick Roemer, (Roemer Software)
Publisher's description - “Free sound recorder software. Now runs on Windows Vista too! It's the easiest way to record absolutely any sound! Easy enough for anyone to use. This free MP3 audio recorder records in high quality to your selected MP3 bitrate.”
www.roemersoftware.com/free-sound-recorder.html
8% remove it
 
Powered by Should I Remove It?

The file freehiqrec.exe has been seen being distributed by the following 2 URLs.

Scan freehiqrec.exe - Powered by Reason Core Security