ejectdevice.exe

InfoTechKnowledge S.A.

This is installed with Knowhow Healthcheck Sync System.
Publisher:
InfoTechKnowledge S.A.  (signed and verified)

MD5:
c2c0c8556d57fdfcf57b530e067c1bde

SHA-1:
8fb4a0ba046629d7e8a42de9354d68033dfad26b

SHA-256:
83dc169a8001e8b22fc72b349c02eca878df6cf212229c7c29df9db3e834db03

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 11:19:21 AM UTC  (today)

File size:
56.8 KB (58,120 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\knowhow\healthcheck\assets\etc\ejectdevice.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
11/3/2010 12:07:26 PM

Valid to:
11/3/2013 12:07:26 PM

Subject:
CN=InfoTechKnowledge S.A., O=InfoTechKnowledge S.A., L=Villars-sur- Glâne, S=Fribourg, C=CH

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000012C11B68B7D

File PE Metadata
Compilation timestamp:
4/18/2012 3:58:54 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
10.0

CTPH (ssdeep):
768:knwrEGGvAL4nvgW5wUHtyKur/HCch8Ii2UHODODPkuEDjXnR3mXgO3xC+AS8C:nEGGoXWeUHwKk/isK4oP2fOBC+l8C

Entry address:
0x155B

Entry point:
E8, AA, 32, 00, 00, E9, 95, FE, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, F8, CE, 40, 00, 89, 0D, F4, CE, 40, 00, 89, 15, F0, CE, 40, 00, 89, 1D, EC, CE, 40, 00, 89, 35, E8, CE, 40, 00, 89, 3D, E4, CE, 40, 00, 66, 8C, 15, 10, CF, 40, 00, 66, 8C, 0D, 04, CF, 40, 00, 66, 8C, 1D, E0, CE, 40, 00, 66, 8C, 05, DC, CE, 40, 00, 66, 8C, 25, D8, CE, 40, 00, 66, 8C, 2D, D4, CE, 40, 00, 9C, 8F, 05, 08, CF, 40, 00, 8B, 45, 00, A3, FC, CE, 40, 00, 8B, 45, 04, A3, 00, CF, 40, 00, 8D, 45, 08, A3, 0C, CF, 40...
 
[+]

Entropy:
6.3144

Code size:
32 KB (32,768 bytes)

The file ejectdevice.exe has been discovered within the following programs.

Knowhow Healthcheck Sync System  by InfoTechKnowledge S.A.
About 3% of users remove it
 
Powered by Should I Remove It?

Scan ejectdevice.exe - Powered by Reason Core Security