EmsServiceHelper.exe

Credant External Media Shield

Credant Technologies

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘EmsService’.
Publisher:
CREDANT Technologies, Inc.  (signed by Credant Technologies)

Product:
Credant External Media Shield

Description:
Credant external media encryption service helper.

Version:
6.7.0.1402

MD5:
c52f672edbedd2e79125d4ff5a7f5fee

SHA-1:
c8ed2061f18ade44c8ce408266039196c8437002

SHA-256:
c6c308d10127eb79fe880638bacba1ec55e1751bd5b53f9e2265725aff37c7fd

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/23/2024 10:40:29 PM UTC  (today)

File size:
2.2 MB (2,295,136 bytes)

Product version:
6.7.0.1402

Copyright:
Copyright © 2002-2009 CREDANT Technologies, Inc.

Trademarks:
CREDANT®, CREDANT Technologies®, the CREDANT logo, and the We Protect What Matters® tagline are registered trademarks of CREDANT Technologies, Inc. Al

Original file name:
EmsServiceHelper.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Windows\System32\emsservicehelper.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/4/2009 8:00:00 PM

Valid to:
6/24/2010 7:59:59 PM

Subject:
CN=Credant Technologies, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Credant Technologies, L=Addison, S=Texas, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3D659EAC38F076660AA3CCC1FEFC5619

File PE Metadata
Compilation timestamp:
2/25/2010 8:32:19 PM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
49152:ED5A9P05i2+SJmOrrrrrrrrrIJ/SJ/SJ/SJ/SJ/V:ED5/VJdrrrrrrrrrIFSFSFSFSFV

Entry address:
0x3AEB0

Entry point:
48, 83, EC, 28, E8, 67, 73, 00, 00, 48, 83, C4, 28, E9, 0E, FD, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 48, 89, 5C, 24, 08, 48, 89, 74, 24, 10, 57, 48, 83, EC, 30, 4D, 85, C9, 49, 8B, D9, 49, 8B, F0, 48, 8B, FA, 74, 52, 48, 85, C9, 75, 38, E8, 29, 47, 00, 00, 45, 33, C9, 45, 33, C0, 33, D2, 33, C9, 48, C7, 44, 24, 20, 00, 00, 00, 00, C7, 00, 16, 00, 00, 00, E8, BB, 13, 00, 00, B8, 16, 00, 00, 00, 48, 8B, 5C, 24, 40, 48, 8B, 74, 24, 48, 48, 83, C4, 30, 5F, C3, 4D, 85, C0, 74, 22, 48...
 
[+]

Entropy:
6.2452

Code size:
418 KB (428,032 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
EmsService

Command:
emsservicehelper.exe


Scan EmsServiceHelper.exe - Powered by Reason Core Security