eDSLoader.exe

eDataSecurity

HiTRUST Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘eDataSecurity Loader’. This is installed with Acer eDataSecurity Management.
Publisher:
HiTRUST  (signed by HiTRUST Inc.)

Product:
eDataSecurity

Description:
eDataSecurity System Loader( Load and prepare enviroment )

Version:
2, 5, 3024, 130

MD5:
0c356b1a82414f296fc0add623b14238

SHA-1:
5c1de9b551dc8c4b9d87f6fb97459188868bbdb0

SHA-256:
62da67844aa2241e5d7aa4f16fdbc9dd67dbb65230306974804826b19ea2f8c4

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 9:00:42 AM UTC  (today)

File size:
482.8 KB (494,424 bytes)

Product version:
2, 5, 3024, 130

Copyright:
(c) HiTRUST. All rights reserved.

Original file name:
eDSLoader.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
10/13/2005 2:00:00 AM

Valid to:
12/12/2006 12:59:59 AM

Subject:
CN=HiTRUST Inc., OU=CA Product Technical Department, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=HiTRUST Inc., L=Taipei, S=Taiwan, C=TW

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3AB07AD1D154F4A2B9C4001A6162D281

File PE Metadata
Compilation timestamp:
12/8/2006 8:37:37 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
3072:YM3ThUO3CSCV5HeUyqrjq7OeoIzMrjUEXZ+w5UqQRu50S5zgEAh:r1UO3CSCV1eUyq9UEX15Uqeu50S+

Entry address:
0x466D

Entry point:
E8, C2, 03, 00, 00, E9, 36, FD, FF, FF, 3B, 0D, 28, B0, 40, 00, 75, 02, F3, C3, E9, 42, 04, 00, 00, 53, 8A, 5C, 24, 08, F6, C3, 02, 56, 8B, F1, 74, 24, 57, 68, FC, 4B, 40, 00, 8D, 7E, FC, FF, 37, 6A, 0C, 56, E8, 38, 01, 00, 00, F6, C3, 01, 74, 07, 57, E8, 87, F9, FF, FF, 59, 8B, C7, 5F, EB, 13, E8, 40, 05, 00, 00, F6, C3, 01, 74, 07, 56, E8, 71, F9, FF, FF, 59, 8B, C6, 5E, 5B, C2, 04, 00, 6A, 14, 68, 30, 8D, 40, 00, E8, B1, 02, 00, 00, FF, 35, 1C, B7, 40, 00, 8B, 35, AC, 63, 40, 00, FF, D6, 59, 89, 45, E4...
 
[+]

Code size:
20 KB (20,480 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
eDataSecurity Loader

Command:
C:\acer\empowering technology\edatasecurity\edsloader.exe


The file eDSLoader.exe has been discovered within the following program.

Publisher's description - “Using advanced cryptographic technologies, Acer eDataSecurity Managementoffers you greater personal data security and encryption for files and datatransmitted via instant messaging or email.”
www.hiegis.com/acer.jsp
About 1% of users remove it
 
Powered by Should I Remove It?

Scan eDSLoader.exe - Powered by Reason Core Security