Associated Malware Groups
The unsafe files using this name are associated with the malware groups:
File Behavior
FILERECOVERY.EXE has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- Enables an In Process Object/Server - Common with DLL Injections
- Executes a Process
- Writes to another Process's Virtual Memory (Process Hijacking)
- Terminates Processes
- Makes outbound connections to other computers using NETBIOSOUT protocols
- Found on infected systems and resists interrogation by security products
- Uses low level functions to hide itself from the user and from system/security processes
- This Process uses Anti Dissasembly Tricks to avoid analysis by security products
- The Process is polymorphic and can change its structure
- This Process Contains User Mode Rootkit Functionality and can hide itself from the running process list
- Creates system tray popups, messages, errors and security warnings
- Enables a COM Object/Server on the Local Machine
- This Process Deletes Other Processes From Disk
FILERECOVERY.EXE has been the subject of the following behavior:
- Created as a process on disk
- Executed as a Process
- Has code inserted into its Virtual Memory space by other programs
- Terminated as a Process
- Deleted as a process from disk
Country Of Origin
The filename FILERECOVERY.EXE was first seen on May 14 2007 in the following geographical regions of the Prevx community:
- on May 14 2007
- Turkey on May 14 2007
- Europe on Apr 7 2008
- The United States on May 1 2008
- Slovakia on May 1 2008
- Mexico on Aug 8 2008
- Spain on Aug 8 2008
- Ukraine on Oct 27 2008
- The United Kingdom on Jun 8 2009
- Georgia on Mar 12 2010
File Name Aliases
FILERECOVERY.EXE can also use the following file names:
- RECOVERY_DEMO.EXE
- FILERECOVERY_NEW1.EXE
- FILERECOVERYDEMO.EXE
- Рабочий стол
- 31538707.EXE
Filesizes
The following file size has been seen:
- 1,385,928 bytes
- 978,944 bytes
- 1,298,432 bytes
- 2,686,976 bytes
- 1,140,432 bytes
- 510,976 bytes
- 1,299,912 bytes
File Type
The filename FILERECOVERY.EXE refers to many versions of an executable program.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.