Gridinsoft Logo
File Icon

The _recaverit.exe (Wondershare Recoverit) File Analysis

Technical Analysis

File Name _recaverit.exe
File Type
PE32+ executable (GUI) x86-64, for MS Windows
Scanner Version 1.0.227.174
Database Version 2025-10-19 05:00:18 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
34,302,680
File Size (bytes)
2025-10-19
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
0ac815749ec299ce5afa3f13309bf1a7
SHA1
009219745f1c6e8b102a29b4af2c8c76578982af
SHA256
5d927a67b08e8a35269ae159455f091f45bfa03aad68634a48795ec0ac534ea6
SHA512
f41f2d6673941ffa134e405ea3e91936bc4f899a09da15c87b461eb0271a5ad926ae90f0e9eaa41c11374bf41109f7837537e7f80f52a1a3e3033c3dab8dd2b3
ImpHash
f7fd4dd843b4f075ba9ecce44ea7cff5

PE Analysis

Basic Information

Icon
Hash: fc229cb66e3908624afe3bf87249a736
Fuzzy: a088417000d3c39eaa8cf3e790d088dd
dHash: d4b27979b2ccb2b2
Image Base 0x140000000
Entry Point 0x14000a50b
Compilation Time 2025-10-11 07:54:20
Checksum 0x020bc928 (Actual: 0x020bc928)
OS Version 6.0
PEiD Signatures PE32+ executable (GUI) x86-64, for MS Windows
PDB Path F:\devops_yanfa\agent\workspace\p-8e88883bc14c48d0bb7bec3356efde0c\src\x64\Release\Recoverit.pdb
Digital Signature OK
Imports 43 libraries
Exports 0 functions
Resources 13 Resources
Sections 9 Sections

Version Information

FileDescription Wondershare Recoverit
FileVersion 14.0.1.4
InternalName Recoverit
LegalCopyright Copyright © 2025 Wondershare. All rights reserved.
OriginalFilename Wondershare
ProductName Wondershare Recoverit
ProductVersion 14.0.1.4
Translation 0x0804 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 8,519,143 bytes 8,519,168 bytes 5.15 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 265D387A3602931E2BAEC1311BD37467
.rdata 0x00821000 24,189,417 bytes 24,189,440 bytes 7.17 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ A23F488A61257A71BB33E1E31E1F1F86
.data 0x01f33000 404,337 bytes 337,408 bytes 2.69 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE FE333BA87983E5E5F48F336B857E1238
.pdata 0x01f96000 749,484 bytes 749,568 bytes 6.37 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 5F689D4E6EA4D8AEF858CD0C07149523
.idata 0x0204d000 150,104 bytes 150,528 bytes 4.99 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 27C7A6B58F32244A25D02A42D3977425
.tls 0x02072000 1,280 bytes 1,536 bytes 0.01 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 3DE6417FBBE582E83AFE6DDC241F3F35
.00cfg 0x02073000 373 bytes 512 bytes 0.43 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 45B5DF851B26AF8B3223B43876BC7EA4
.rsrc 0x02074000 201,699 bytes 201,728 bytes 3.71 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 6A5B8AAF9CC23F2553B00203FE6F0BB0
.reloc 0x020a6000 130,253 bytes 130,560 bytes 2.29 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 9CA3022BEADD87AB9E9C8DAD0C6EB11E
Entropy Analysis Alert

1 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 13 (166,883 bytes)
Resource Type Count Total Size Percentage
RT_ICON 10 165,344 bytes
99.1%
RT_GROUP_ICON 1 146 bytes
0.1%
RT_VERSION 1 744 bytes
0.4%
RT_MANIFEST 1 649 bytes
0.4%

Certificate Chain Analysis

Certificate Information
Product Wondershare Recoverit
Description Wondershare Recoverit
File Version 14.0.1.4
Original Name Wondershare
Signing Date 07:58 AM 10/11/2025 (90 days ago)
Verification Status Signed
Signers Wondershare Technology Group Co.,Ltd; DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1; DigiCert Trusted Root G4; DigiCert
Counter Signers DigiCert SHA256 RSA4096 Timestamp Responder 2025 1; DigiCert Trusted G4 TimeStamping RSA4096 SHA256 2025 CA1; DigiCert Trusted Root G4; DigiCert
Internal Name Recoverit
Copyright Copyright © 2025 Wondershare. All rights reserved.
Certificate Chain Summary
DigiCert Trusted Root G4 #1 Primary
Validity Period: 2022-08-01 00:00:00 → 2031-11-09 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 0E 9B 18 8E F9 D0 2D E7 EF DB 50 E2 08 40 18 5A
DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 #2 Chain
Validity Period: 2021-04-29 00:00:00 → 2036-04-28 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 08 AD 40 B2 60 D2 9C 4C 9F 5E CD A9 BD 93 AE D9
DigiCert Trusted G4 TimeStamping RSA4096 SHA256 2025 CA1 #3 Chain
Validity Period: 2025-05-07 00:00:00 → 2038-01-14 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 0D C7 AC 57 05 FF 21 99 2E 40 43 22 0C 3A 49 86
DigiCert SHA256 RSA4096 Timestamp Responder 2025 1 #4 Chain
Validity Period: 2025-06-04 00:00:00 → 2036-09-03 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 0A 80 EF 18 4B 8D F1 05 82 D1 C4 76 A7 95 74 68
Wondershare Technology Group Co.,Ltd #5 Chain
Validity Period: 2025-04-03 00:00:00 → 2028-04-07 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 03 E3 81 47 3F 5E 72 D2 A2 B7 9C 28 B4 A2 C6 B9

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

OK

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.

Your Score for
/

Gridinsoft Anti-Malware

Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware

Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!

Gridinsoft Anti-Malware