usbsafelyremovesetup_5-1-3.exe

USB Safely Remove

Crystal Rich Ltd

The program is a setup application that uses the Inno Setup installer. This is installed with multiple programs including USB Safely Remove 5.1 and USB Safely Remove. The file has been seen being downloaded from safelyremove.com.
Publisher:
SafelyRemove.com   (signed by Crystal Rich Ltd)

Product:
USB Safely Remove

Description:
USB Safely Remove Setup

Version:
5.1.3.1186

MD5:
ccb2323729c8e2dfaf8f84ef81212925

SHA-1:
a237d6a9e8a2984c5d1a949c970c7f42a85ec91c

SHA-256:
0a931d23e7c023b1f0ba824b38c3bf62bd60b99980dd12b070770ccf57d8ee26

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2024 11:42:18 PM UTC  (a few moments ago)

File size:
5.5 MB (5,787,160 bytes)

Product version:
5.1.3.1186

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\usbsafelyremovesetup_5-1-3.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
12/12/2011 6:00:00 PM

Valid to:
12/12/2012 5:59:59 PM

Subject:
CN=Crystal Rich Ltd, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Crystal Rich Ltd, L=Saint Petersburg, S=Saint Petersburg, C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
20C53F7597B1AB70BDA6CF9DE847708E

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:gaNtfrN5pgClIadELl6+aqdx0ct0JeGeH7HbPdJcLO+Ieuw88h99Lwb2Ri0O5zD:3tfrNXRl17+5xXCg77FJcduwnhHvOR

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, E8, CD, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, E8, CD...
 
[+]

Entropy:
7.9977

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file usbsafelyremovesetup_5-1-3.exe has been discovered within the following programs.

USB Safely Remove  by Crystal Rich Ltd
Publisher's description - “Safely remove a device via the convenient menu or a hotkey, remove unneded devices from the menu, setup icons or names for the devices. Besides even if you stop a device accidentally you can return it in a click.”
safelyremove.com
56% remove it
USB Safely Remove 5.1  by SafelyRemove.com
Publisher's description - “USB Safely Remove is a USB device manager. It saves time and extends user abilities on active work with flash drives, portable drives, card readers and other gadgets.”
www.safelyremove.com
57% remove it
 
Powered by Should I Remove It?

The file usbsafelyremovesetup_5-1-3.exe has been seen being distributed by the following URL.

Scan usbsafelyremovesetup_5-1-3.exe - Powered by Reason Core Security