usbsafelyremove.exe

USBSafelyRemove

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘USB Safely Remove’.
Product:
USBSafelyRemove

Description:
Safely Remove A Device In One Click

Version:
4.0.6.720

MD5:
197c2bdc5b5ac4b515ef6cfb1e33971e

SHA-1:
8fe3fc516dc02ded9e66952b61aa1fed0a54e2e0

SHA-256:
cf1debbe8e2c082a5b5320d7d5e1cabdd6916bee2b0871c15e208ee1b1f8dd64

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
12/24/2025 9:40:48 PM UTC  (today)

Scan engine
Detection
Engine version

Comodo Security
Heur.Suspicious
17172

File size:
1.1 MB (1,147,904 bytes)

Product version:
4.0.6.720

Copyright:
Copyright © 2004-2008 by SafelyRemove.com

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\usb safely remove\usbsafelyremove.exe

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:RsScQKJKCDAh5WfFzh3XOx+TFSBPV/5KcQmXT9Uc0dDqQ:RsSNKACDAhaFzh3+xkFIV/ohmj2c0deQ

Entry address:
0x1000

Entry point:
68, 01, 20, 6A, 00, E8, 01, 00, 00, 00, C3, C3, 93, 62, 43, FC, A3, D6, D9, E5, 9E, A1, 52, 3B, 0D, 38, 11, 5A, 8C, D5, 5D, 95, EC, 40, 53, 6C, 52, 7D, C2, 5A, C2, CB, 40, 4E, AC, 8A, 01, 1E, 08, D6, CA, 12, 64, 9F, 7A, 5B, BF, EB, F8, C3, FD, BB, 1C, 4E, DC, 42, E6, 91, 9F, 00, EF, CE, 51, 8A, 23, 38, D6, CC, B2, DF, AF, 57, E9, 6B, 12, 9B, 00, F3, EA, 0A, E4, 66, D8, 72, 8D, 37, B5, C7, 62, CD, 66, 89, 0E, AE, C3, CC, E6, D5, 80, C7, 29, 7A, BB, 99, B3, 10, 43, 68, 63, 77, 3D, 01, ED, E7, 54, 6B, EF, BD...
 
[+]

Entropy:
7.9139

Packer / compiler:
ASProtect v1.2x (New Strain)

Code size:
1.6 MB (1,701,376 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
USB Safely Remove

Command:
C:\Program Files\usb safely remove\usbsafelyremove.exe \startup


Scan usbsafelyremove.exe - Powered by Reason Core Security