How to remove RecoverKeys.exe
- File Details
- Overview
- Analysis
RecoverKeys.exe
The module RecoverKeys.exe has been detected as Adware.OpenCandy
File Details
| Product Name: |
|
| Company Name: |
|
| MD5: |
3c9e4b20f50e960aa1b8d185b723de5c |
| Size: |
39 MB |
| First Published: |
2025-11-05 23:01:31 (2 months ago) |
| Latest Published: |
2025-11-05 23:01:32 (2 months ago) |
| Status: |
Adware.OpenCandy (on last analysis) |
|
| Analysis Date: |
2025-11-05 23:01:32 (2 months ago) |
Overview
| Signed By: |
ONE UP LTD. |
| Status: |
Invalid (digital signature could be stolen or file could be patched) |
| %mydoc%\ncrecoverkeysportable\app |
| %mydoc%\sauvegarde samsung 970 512 go\sauvegarde 16_05_2024\documents\recoverkey\ncrecoverkeysportable\app |
Analysis
| Subsystem: |
Windows GUI |
| PE Type: |
pe |
| OS Bitness: |
64 |
| Image Base: |
0x0000000000400000 |
| Entry Address: |
0x014c8520 |
| Name |
Size of data |
MD5 |
| .text |
21789696 |
aa701145259417d1c3c6f03c912730de |
| .data |
2274816 |
8115d5dd40f2e3f56bb561ca013ef488 |
| .bss |
0 |
d41d8cd98f00b204e9800998ecf8427e |
| .idata |
30208 |
0624ae61b4947b8e0b7f803f5892458d |
| .didata |
3584 |
a40b55d0f0a95738438c40690ce522e1 |
| .tls |
0 |
d41d8cd98f00b204e9800998ecf8427e |
| .rdata |
512 |
8617dddebb8ece37a6f178322f00ebaf |
| .pdata |
1241600 |
b8f4ba5a7f8ae91bcdf6dae8df91055f |
| .rsrc |
15734784 |
975a24d0bae0f2bbda3ee992ecf57f7f |