ramcache.exe

FNet Co., Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘RamCache II’. This is installed with RamCache II.
Publisher:
ASUSTeKcomputer Inc  (signed by FNet Co., Ltd.)

Description:
RAM Cache II

Version:
1.1.4.0

MD5:
0e72a281c81b74076841a83b554a27b7

SHA-1:
c8b02f5901cabe128f60bfbacf24fff494ebcdc5

SHA-256:
649eeec2e67b4eec967f811fb87f34ffc7c5c06ddc51c1b260f018c49239c88e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/1/2024 2:44:06 AM UTC  (today)

File size:
4.1 MB (4,351,080 bytes)

Product version:
4.00

Copyright:
Copyright (C) 2016 FNet

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\ramcache ii\ramcache.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
11/4/2015 4:00:00 PM

Valid to:
12/15/2017 3:59:59 PM

Subject:
CN="FNet Co., Ltd.", O="FNet Co., Ltd.", L=Chiayi city, S=Taiwan, C=TW

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2DC246906BA461BC6ADE35AEE9D16448

File PE Metadata
Compilation timestamp:
9/20/2016 2:54:47 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.0

CTPH (ssdeep):
49152:upoU6WJ8GElYfxhhgwTTJnsrYirVsjcAKN96jH31tZ:yvTxhhlwVsCY

Entry address:
0x1878

Entry point:
EB, 10, 66, 62, 3A, 43, 2B, 2B, 48, 4F, 4F, 4B, 90, E9, 98, 20, 57, 00, A1, 8B, 20, 57, 00, C1, E0, 02, A3, 8F, 20, 57, 00, 52, 6A, 00, E8, 89, EF, 16, 00, 8B, D0, E8, AA, 30, 16, 00, 5A, E8, 08, 30, 16, 00, E8, DF, 30, 16, 00, 6A, 00, E8, 0C, 46, 16, 00, 59, 68, 34, 20, 57, 00, 6A, 00, E8, 63, EF, 16, 00, A3, 93, 20, 57, 00, 6A, 00, E9, 27, A5, 16, 00, E9, 3A, 46, 16, 00, 33, C0, A0, 7D, 20, 57, 00, C3, A1, 93, 20, 57, 00, C3, 60, BB, 00, 50, B0, BC, 53, 68, AD, 0B, 00, 00, C3, B9, D8, 00, 00, 00, 0B, C9...
 
[+]

Entropy:
6.5269

Code size:
1.4 MB (1,511,424 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
RamCache II

Command:
"C:\Program Files\ramcache ii\ramcache.exe"


The file ramcache.exe has been discovered within the following program.

RamCache II  by ASUSTeKcomputer Inc
About 2% of users remove it
 
Powered by Should I Remove It?

Scan ramcache.exe - Powered by Reason Core Security