SATAUnplug.exe

eSATA I/F, eSATA storage

I-O DATA DEVICE, INC.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘SATAUnplug’. This is installed with SATAUnplug.
Publisher:
I-O DATA DEVICE, INC.  (signed and verified)

Product:
eSATA I/F, eSATA storage

Description:
SATAUnplug

Version:
1, 1, 0, 27

MD5:
84d27c819d20c38b4f132602b94ba2d8

SHA-1:
ba091df9754bdd43aabc3d9476c53472ba744b03

SHA-256:
ffdcb6986b8832f2af041389b6060dbdd6268ca7e550ab8d56f441cff35d5040

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 4:37:18 AM UTC  (today)

File size:
502.6 KB (514,688 bytes)

Product version:
1.10

Copyright:
Copyright (C) 2005-2009 I-O DATA DEVICE, INC.

Original file name:
SATAUnplug.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\i-o data\sataunplug\sataunplug.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
12/15/2008 9:00:00 AM

Valid to:
12/16/2009 8:59:59 AM

Subject:
CN="I-O DATA DEVICE, INC.", OU=Technical Support Dept., OU=Digital ID Class 3 - Microsoft Software Validation v2, O="I-O DATA DEVICE, INC.", L=Kanazawa-shi, S=Ishikawa, C=JP

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7515B84EE2B81F32FD5583B9274EC92E

File PE Metadata
Compilation timestamp:
10/15/2009 11:03:42 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:pb/RhAUo3ayZf8GDVOLtLLPxT53X8l8iLTI9y77wQ3xHoMilf7rMpp+ST2xIa:pb/RhAU3Sf8GDkLFPVlXGdM9yvQfmxS

Entry address:
0x13FD3

Entry point:
6A, 60, 68, F8, 04, 45, 00, E8, 89, 4B, 00, 00, BF, 94, 00, 00, 00, 8B, C7, E8, D5, 16, 00, 00, 89, 65, E8, 8B, F4, 89, 3E, 56, FF, 15, A0, C4, 44, 00, 8B, 4E, 10, 89, 0D, B4, 39, 46, 00, 8B, 46, 04, A3, C0, 39, 46, 00, 8B, 56, 08, 89, 15, C4, 39, 46, 00, 8B, 76, 0C, 81, E6, FF, 7F, 00, 00, 89, 35, B8, 39, 46, 00, 83, F9, 02, 74, 0C, 81, CE, 00, 80, 00, 00, 89, 35, B8, 39, 46, 00, C1, E0, 08, 03, C2, A3, BC, 39, 46, 00, 33, F6, 56, 8B, 3D, 18, C4, 44, 00, FF, D7, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03...
 
[+]

Entropy:
6.5521

Developed / compiled with:
Microsoft Visual C++ v7.0

Code size:
300 KB (307,200 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
SATAUnplug

Command:
"C:\Program Files\i-o data\sataunplug\sataunplug.exe"


The file SATAUnplug.exe has been discovered within the following program.

SATAUnplug  by I-O DATA DEVICE, INC.
www.iodata.jp
About 8% of users remove it
 
Powered by Should I Remove It?

Scan SATAUnplug.exe - Powered by Reason Core Security