EmsServiceHelper.exe

Credant External Media Shield

Credant Technologies

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘EmsService’.
Publisher:
CREDANT Technologies, Inc.  (signed by Credant Technologies)

Product:
Credant External Media Shield

Description:
Credant external media encryption service helper.

Version:
5.3.2.590

MD5:
7269a4563b702a5af3df9f6bc4c6e0fb

SHA-1:
2e89fee418dc29d83b6ad810e055acb9c0b506be

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/1/2024 7:16:15 PM UTC  (today)

File size:
481.3 KB (492,848 bytes)

Product version:
5.3.2.590

Copyright:
Copyright© 2002-2007, All rights reserved

Trademarks:
CREDANT®, CREDANT Technologies®, the CREDANT logo, and the Be mobile, Be secure® tagline are registered trademarks of CREDANT Technologies, Inc. All o

Original file name:
EmsServiceHelper.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Windows\System32\emsservicehelper.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/4/2007 8:00:00 PM

Valid to:
9/23/2008 7:59:59 PM

Subject:
CN=Credant Technologies, OU=Credant Mobile Guardian, O=Credant Technologies, L=Addison, S=Texas, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7ABE1E6429E602375B7B2070D17D809F

File PE Metadata
Compilation timestamp:
4/29/2008 1:43:09 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:BfhegOMUXfbtahAZfiAiw2SBDbUIjuJX17hFat3BjBNir1gkz5AxndrHzr1gkz5q:th2MUXHigtbUFJX17hFat0Sv1zSYC

Entry address:
0x1E41F

Entry point:
E8, D1, 5A, 00, 00, E9, 16, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, 55, 8B, EC, 57, 56, 8B, 75, 0C, 8B, 4D, 10, 8B, 7D, 08, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, A4, 01, 00, 00, 81, F9, 00, 01, 00, 00, 72, 1F, 83, 3D, E0, 1A, 46, 00, 00, 74, 16, 57, 56, 83, E7, 0F, 83, E6, 0F, 3B, FE, 5E, 5F, 75, 08, 5E, 5F, 5D, E9, 99, 5B, 00, 00, F7, C7, 03, 00, 00, 00, 75, 15, C1, E9, 02, 83, E2, 03, 83, F9, 08, 72, 2A, F3, A5, FF, 24, 95, A4, E5, 41, 00, 90, 8B, C7, BA, 03, 00, 00, 00, 83, E9, 04, 72...
 
[+]

Entropy:
6.2476

Code size:
284 KB (290,816 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
EmsService

Command:
emsservicehelper.exe


Scan EmsServiceHelper.exe - Powered by Reason Core Security