RME.exe

CE-Infosys GmbH

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Removable Media Utility’.
Publisher:
CE-Infosys  (signed by CE-Infosys GmbH)

Description:
Removable Media Encryption

Version:
1, 7, 5, 0

MD5:
bf2d9c959a4ecf04ddfd46ffa68daf85

SHA-1:
c92a554ca0a57460886469e161edff0a14c7733b

SHA-256:
71e1845eba2e9a18bb3395fc9297db735c5446ebfad885d81abd0decb35b8970

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 10:03:42 PM UTC  (today)

File size:
774.8 KB (793,408 bytes)

Product version:
0, 0, 0, 0

Copyright:
Copyright (c) 2002-2008 CE-Infoys

Original file name:
RME.exe

File type:
Executable application (Win64 EXE)

Common path:
C:\Program Files\ce-infosys\compusec\rme.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
1/19/2010 11:25:09 PM

Valid to:
1/19/2013 11:25:04 PM

Subject:
E=info@ce-infosys.com, CN=CE-Infosys GmbH, O=CE-Infosys GmbH, L=Bodenheim, S=Rheinland-Pfalz, C=DE

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
010000000001264723FE90

File PE Metadata
Compilation timestamp:
9/4/2009 5:20:23 PM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
8.0

Entry address:
0x485B0

Entry point:
48, 83, EC, 28, E8, B7, C8, 00, 00, 48, 83, C4, 28, E9, 0E, FD, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 48, 83, EC, 38, 48, C7, 44, 24, 20, 00, 00, 00, 00, E8, 4E, C9, 00, 00, 48, 83, C4, 38, C3, CC, CC, CC, CC, CC, CC, CC, CC, CC, 48, 8B, C1, 0F, B7, 10, 48, 83, C0, 02, 66, 85, D2, 75, F4, 48, 2B, C1, 48, D1, F8, 48, 83, E8, 01, C3, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 66, 66, 66, 90, 66, 66, 66, 90, 66, 90, 48, 8B, C1, 48, F7, D9, 48, A9, 07, 00, 00, 00, 74, 0F, 66, 90...
 
[+]

Entropy:
6.4337

Code size:
386 KB (395,264 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Removable Media Utility

Command:
C:\Program Files\ce-infosys\compusec\rme.exe


Scan RME.exe - Powered by Reason Core Security