undelete-360.exe

Undelete 360

Kirill Chermenin

The application undelete-360.exe, “Undelete 360 - Freeware” by Kirill Chermenin has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This file is typically installed with the program Undelete 360 FULL by File Recovery Ltd.. While running, it connects to the Internet address hz4.chermenin.com on port 80 using the HTTP protocol.
Publisher:
File Recovery Ltd.  (signed by Kirill Chermenin)

Product:
Undelete 360

Description:
Undelete 360 - Freeware

Version:
2.1.6.25

MD5:
758e8b3f31a684e014285333f9eaad4a

SHA-1:
1154486d73541878cfb0b7fdac6a2deb74c52c58

SHA-256:
acc80392a51fa64f72bc09cf7c6005939d1fc0ff1693159cbe4a6c3ed8c133d5

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/25/2024 11:27:29 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.KirillChermenin.M
14.2.4.17

File size:
7.8 MB (8,192,640 bytes)

Product version:
2.1.6.25

Copyright:
Copyright, 2013 File Recovery Ltd.

Original file name:
undelete-360.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\file recovery\undelete360\undelete-360.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
1/8/2013 7:00:00 PM

Valid to:
1/9/2016 6:59:59 PM

Subject:
CN=Kirill Chermenin, O=Kirill Chermenin, STREET=70 Let Oktyabrya 17-50, L=Krasnodar, S=Krasnodarsky kray, PostalCode=350089, C=RU

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00BADFCFEBF80484E1CF8E39A8B7F16D8A

File PE Metadata
Compilation timestamp:
2/28/2013 8:08:32 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
196608:0EAOyFLQk0euqpjrWlTktvzWwCPSm6/SDvRcD49:0nOTktvp58aDa

Entry address:
0x5E7478

Entry point:
55, 8B, EC, 83, C4, EC, 53, 56, 33, C0, 89, 45, EC, B8, B8, AF, 9D, 00, E8, 55, 8B, A2, FF, 8B, 1D, 44, A2, A1, 00, 8B, 35, C4, A3, A1, 00, 33, C0, 55, 68, 18, 76, 9E, 00, 64, FF, 30, 64, 89, 20, 8B, 0B, B2, 01, A1, 64, 5A, 9C, 00, E8, 79, 4C, C2, FF, 89, 06, A1, D0, A0, A1, 00, 8B, 00, BA, 34, 76, 9E, 00, E8, A6, 3D, FE, FF, 85, C0, 7E, 1B, A1, D0, A0, A1, 00, 8B, 00, BA, 34, 76, 9E, 00, E8, 91, 3D, FE, FF, 8B, 15, 54, 9C, A1, 00, 89, 02, EB, 0B, A1, 54, 9C, A1, 00, C7, 00, 10, 27, 00, 00, 8D, 4D, EC, A1...
 
[+]

Entropy:
6.6492

Developed / compiled with:
Microsoft Visual C++

Code size:
5.9 MB (6,186,496 bytes)

The file undelete-360.exe has been discovered within the following program.

Undelete 360 FULL  by File Recovery Ltd.
www.undelete360.com
About 5% of users remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to hz4.chermenin.com  (138.201.200.72:80)

TCP:
Connects to ip-172-16-2-8.ec2.internal  (172.16.2.8:3128)

Remove undelete-360.exe - Powered by Reason Core Security