usbsafelyremove.exe

USBSafelyRemove

Crystal Rich, Ltd

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘USB Safely Remove’.
Publisher:
Crystal Rich, Ltd  (signed and verified)

Product:
USBSafelyRemove

Description:
USB and SATA Device Manager

Version:
4.2.5.879

MD5:
6a83d9eb85b666d8474b96ade5ad5887

SHA-1:
9265ee7cb093a0eb61f38f9a6ad2ef4cfc28a3e5

SHA-256:
b72e6b5c72fe767a0ddd3223bdbf7458c09de87a5e8eb921775ac37dbbf6c1ec

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/16/2024 5:20:08 AM UTC  (today)

File size:
1.5 MB (1,521,488 bytes)

Product version:
4.2.5.879

Copyright:
Copyright © 2009 by Crystal Rich Ltd

File type:
Executable application (Win32 EXE)

Language:
English (United Kingdom)

Common path:
C:\Program Files\usb safely remove\usbsafelyremove.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/23/2009 1:00:00 AM

Valid to:
11/25/2010 12:59:59 AM

Subject:
CN="Crystal Rich, Ltd", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Crystal Rich, Ltd", L=Saint Petersburg, S=Saint Petersburg, C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
54B3167B86CDCBCEA4DF714F2DB82384

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:SwOGpzgtHHLv6wettE1zrPabAgFA0kH0eQnIym0ILUzjmFNJBQmXMY+CnkHi5:XgV6weMiPF9kUAym0qUX84mZ+CnkHi5

Entry address:
0x1000

Entry point:
68, 01, F0, 71, 00, E8, 01, 00, 00, 00, C3, C3, 95, BA, 57, 9D, C1, 80, 3E, 34, 20, 39, 89, 01, 3C, F6, A6, 3C, 1C, C5, 8C, 7A, 4C, DE, 4D, 29, 19, 7C, 00, 84, 19, AA, 29, 44, 6E, E8, 47, 84, 01, 64, 5F, 5A, 99, E4, 22, F0, B4, 15, 63, 87, 7E, 68, B0, C6, 3E, 11, 72, AD, 89, F4, 63, E0, B5, D1, 2E, C0, 45, F4, 19, 9C, 43, C1, F0, 29, AA, 8A, 41, 63, 6B, 0E, 57, 58, 0D, C8, C6, 09, 4D, BB, 0F, EE, C0, 03, 3C, 90, CD, 22, 72, 74, 5E, 89, 9A, 74, CB, 8F, AB, 66, 96, 31, E9, 9E, D6, A5, B4, E6, 8E, AC, C6, 42...
 
[+]

Packer / compiler:
ASProtect v1.2x (New Strain)

Code size:
1.9 MB (1,996,288 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
USB Safely Remove

Command:
C:\Program Files\usb safely remove\usbsafelyremove.exe \startup


Scan usbsafelyremove.exe - Powered by Reason Core Security