EmsService.exe

Credant External Media Shield

Credant Technologies

It runs as a separate (within the context of its own process) windows Service named “EMS”.
Publisher:
CREDANT Technologies, Inc.  (signed by Credant Technologies)

Product:
Credant External Media Shield

Description:
External Media Encryption Service.

Version:
7.3.0.4564

MD5:
f43975b256f0ac0789c8ae5cfdabb1d9

SHA-1:
643428a36da86437efd1b81f1da9bff405452459

SHA-256:
1ce228d479e3fca946d99e765fb0887e121214a9bc8afe821aa6e3479bca6659

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 11:32:48 PM UTC  (a few moments ago)

File size:
1.1 MB (1,152,648 bytes)

Product version:
7.3.0.4564

Copyright:
Copyright© 2002-2012 CREDANT Technologies, Inc.

Trademarks:
CREDANT®, CREDANT Technologies®, and the CREDANT logo® tagline are registered trademarks of CREDANT Technologies, Inc. All other trademarks used herei

Original file name:
EmsService.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Windows\System32\emsservice.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/21/2011 1:00:00 AM

Valid to:
6/24/2014 12:59:59 AM

Subject:
CN=Credant Technologies, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Credant Technologies, L=Addison, S=Texas, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0C53F2921BBD484F0E998B0FA02A3DF2

File PE Metadata
Compilation timestamp:
7/25/2012 10:38:39 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

CTPH (ssdeep):
24576:QX5LSsbHl149yCxn0jXTAVDtCGWwuTFLNpu89TIrnh:QXxXHl18zn0r6kFLNpfTIrnh

Entry address:
0x5291A

Entry point:
E8, 9A, BF, 00, 00, E9, 41, FE, FF, FF, 8B, 44, 24, 04, 66, 8B, 54, 24, 08, EB, 07, 66, 3B, CA, 74, 11, 40, 40, 0F, B7, 08, 66, 85, C9, 75, F1, 66, 39, 10, 74, 02, 33, C0, C3, 8B, 44, 24, 04, 0F, B7, 10, 66, 85, D2, 53, 56, 57, 74, 2A, 8B, 5C, 24, 14, 0F, B7, 3B, 66, 85, FF, 8B, F3, 74, 12, 0F, B7, CF, 66, 3B, CA, 74, 16, 46, 46, 0F, B7, 0E, 66, 85, C9, 75, F1, 40, 40, 0F, B7, 10, 66, 85, D2, 75, DD, 33, C0, 5F, 5E, 5B, C3, 8B, 44, 24, 04, 85, C0, 74, 12, 83, E8, 08, 81, 38, DD, DD, 00, 00, 75, 07, 50, E8...
 
[+]

Entropy:
6.2914

Code size:
764 KB (782,336 bytes)

Service
Display name:
EMS

Description:
Encrypts files on external media

Type:
Win32OwnProcess

Group:
Device Security

Depends on:
CmgShieldCEF


Scan EmsService.exe - Powered by Reason Core Security