How to remove RecoverKeys.exe
- File Details
- Overview
- Analysis
RecoverKeys.exe
The module RecoverKeys.exe has been detected as Adware.OpenCandy
File Details
| Product Name: |
|
| Company Name: |
|
| MD5: |
b82d00c98653f6c37ec48f0d7cc44c01 |
| Size: |
30 MB |
| First Published: |
2025-11-05 23:01:31 (a week ago) |
| Latest Published: |
2025-11-05 23:01:31 (a week ago) |
| Status: |
Adware.OpenCandy (on last analysis) |
|
| Analysis Date: |
2025-11-05 23:01:31 (a week ago) |
Overview
| Signed By: |
ONE UP LTD. |
| Status: |
Invalid (digital signature could be stolen or file could be patched) |
| %mydoc%\sauvegarde samsung 970 512 go\sauvegarde 16_05_2024\documents\recoverkey\ncrecoverkeysportable\app |
Analysis
| Subsystem: |
Windows GUI |
| PE Type: |
pe |
| OS Bitness: |
32 |
| Image Base: |
0x00400000 |
| Entry Address: |
0x00dedea0 |
| Name |
Size of data |
MD5 |
| .text |
14569472 |
a230061292c03e6e793ef89abdadaffc |
| .itext |
33280 |
1e5f6c3fcf6a9f8dc91bb417ace0ae39 |
| .data |
402944 |
655ce9a99f6eda0891db4446997b9e91 |
| .bss |
0 |
d41d8cd98f00b204e9800998ecf8427e |
| .idata |
23040 |
4c4be8eab8cc71df300f348b1a074900 |
| .didata |
2560 |
046c97d2a9df723a9ec104716557e900 |
| .tls |
0 |
d41d8cd98f00b204e9800998ecf8427e |
| .rdata |
512 |
bf03045f047fad8701cf8a35dcbd69ca |
| .reloc |
1204736 |
0a5f6dc80742fc077742fd394b41c90c |
| .rsrc |
15734784 |
73c71a88e08dffbde17d8ae1d4c3159e |