usbsafelyremove.exe

USB Safely Remove

Crystal Rich Ltd

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘USB Safely Remove’.
Publisher:
Crystal Rich Ltd  (signed and verified)

Product:
USB Safely Remove

Description:
USB Safely Remove - an enhanced replacement for Windows safe removal tool

Version:
5.2.1.1195

MD5:
2e99b6da17a42d89323cad77b994d9bc

SHA-1:
793adf82bba85f8d49295f8fbab2c3fbeba6eeec

SHA-256:
87dc03c0134e94de34b0c69a96ae078fe84d272eb651ec86d2feaa0223cde96a

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2024 5:52:13 PM UTC  (today)

File size:
2.4 MB (2,546,943 bytes)

Product version:
5.2.1.1195

Copyright:
Copyright © 2013 by Crystal Rich Ltd

File type:
Executable application (Win32 EXE)

Language:
English (United Kingdom)

Common path:
C:\Program Files\usb safely remove\usbsafelyremove.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
12/15/2012 4:00:00 PM

Valid to:
1/15/2014 3:59:59 PM

Subject:
CN=Crystal Rich Ltd, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Crystal Rich Ltd, L=Saint Petersburg, S=Saint Petersburg, C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1A3971F7D5A04EBA878183D0A57E1EC1

File PE Metadata
Compilation timestamp:
3/13/2013 12:54:31 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x1000

Entry point:
E9, A5, 7D, 11, 00, E8, 01, 00, 00, 00, C3, C3, 13, C1, 6D, 13, BD, B7, D4, 79, 3A, 44, 77, AC, B3, 8A, 9A, FA, 38, A0, 4F, 39, 80, 81, 4C, E6, DD, 83, 5F, 8B, 58, 59, 36, EF, E3, 31, 49, 60, C0, D1, 16, B6, 69, 89, 23, C8, 54, 6C, 29, 01, F1, 15, 31, 08, E4, F0, CD, 66, 5B, A4, D4, 7A, 39, 50, CD, FD, 26, 6B, 93, 38, B5, 8B, 3F, E9, 6D, F4, 06, A5, A1, D6, 91, B8, 06, 5D, F1, 01, 33, 98, 9E, 67, A0, 78, 2A, 75, E3, A1, ED, 4F, 21, F6, 06, 3B, AD, 5A, 4C, 2E, 1E, FB, C7, 8F, FE, 37, CE, A5, F6, F0, F1, 6B...
 
[+]

Entropy:
7.6482

Packer / compiler:
Xtreme-Protector v1.05

Code size:
3.9 MB (4,071,936 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
USB Safely Remove

Command:
C:\Program Files\usb safely remove\usbsafelyremove.exe \startup


Scan usbsafelyremove.exe - Powered by Reason Core Security