EmsServiceHelper.exe

Credant External Media Shield

Credant Technologies

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘EmsService’.
Publisher:
CREDANT Technologies, Inc.  (signed by Credant Technologies)

Product:
Credant External Media Shield

Description:
Credant external media encryption service helper.

Version:
6.8.0.2123

MD5:
e998a7b1a39e788049a8da44a768cd4e

SHA-1:
a40facf59e2bed93f030be40726d6e3c15b6cc38

SHA-256:
78980f059ef7e358dd381a89552310c7ffb1c4456406ce4993f4920f68e4f29b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 7:30:42 AM UTC  (today)

File size:
2 MB (2,049,448 bytes)

Product version:
6.8.0.2123

Copyright:
Copyright © 2002-2010 CREDANT Technologies, Inc.

Trademarks:
CREDANT®, CREDANT Technologies®, the CREDANT logo, and the We Protect What Matters® tagline are registered trademarks of CREDANT Technologies, Inc. Al

Original file name:
EmsServiceHelper.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Windows\System32\emsservicehelper.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/14/2010 7:00:00 PM

Valid to:
6/24/2011 6:59:59 PM

Subject:
CN=Credant Technologies, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Credant Technologies, L=Addison, S=Texas, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
416C08675D64AA776021F9FF5C8201EF

File PE Metadata
Compilation timestamp:
7/1/2010 3:43:55 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
49152:T+/+YVirrrrrrrrrIJ/SJ/SJ/SJ/SJ/2:TiVirrrrrrrrrIFSFSFSFSF

Entry address:
0x1FE5F

Entry point:
E8, 35, 61, 00, 00, E9, 17, FE, FF, FF, 55, 8B, EC, 56, 8B, 75, 14, 57, 33, FF, 3B, F7, 75, 04, 33, C0, EB, 65, 39, 7D, 08, 75, 1B, E8, 8F, 2B, 00, 00, 6A, 16, 5E, 89, 30, 57, 57, 57, 57, 57, E8, F8, 0B, 00, 00, 83, C4, 14, 8B, C6, EB, 45, 39, 7D, 10, 74, 16, 39, 75, 0C, 72, 11, 56, FF, 75, 10, FF, 75, 08, E8, 6F, 0F, 00, 00, 83, C4, 0C, EB, C1, FF, 75, 0C, 57, FF, 75, 08, E8, 4E, 0E, 00, 00, 83, C4, 0C, 39, 7D, 10, 74, B6, 39, 75, 0C, 73, 0E, E8, 40, 2B, 00, 00, 6A, 22, 59, 89, 08, 8B, F1, EB, AD, 6A, 16...
 
[+]

Entropy:
6.1975

Code size:
280 KB (286,720 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
EmsService

Command:
emsservicehelper.exe


Scan EmsServiceHelper.exe - Powered by Reason Core Security