crschksvc.exe

Cross Check Application Services

LG CNS Co.,Ltd

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘PsmSvc’.
Publisher:
LG CNS  (signed by LG CNS Co.,Ltd)

Product:
Cross Check Application Services

Version:
1, 0, 0, 1

MD5:
f5422fcd893646de0fc5e55c4c2791d2

SHA-1:
85044ca4f956f0ee631c94544814b49b3ed5db72

SHA-256:
e5a804c705251b16aa083ff657b11ecda6876198d90805282f53e58d42945c65

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
7/3/2025 9:48:44 AM UTC  (today)

File size:
269.5 KB (275,944 bytes)

Product version:
1, 0, 0, 1

Copyright:
LG CNS Copyright (C) 2016

Original file name:
crschksvc.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\lgcns\psm\agent\bin\crschksvc.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
3/2/2015 9:00:00 AM

Valid to:
4/1/2017 8:59:59 AM

Subject:
CN="LG CNS Co.,Ltd", O="LG CNS Co.,Ltd", L=Jung-gu, S=Seoul, C=KR

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
7542BA6EB93487BDC913A340F80280E2

File PE Metadata
Compilation timestamp:
8/18/2016 6:40:56 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:ItM8hI+RQ83PWJBOVI9oOfyB7zt73yV52JPN+:It5a+bIOztDyVo+

Entry address:
0x1443C

Entry point:
E8, C6, 9A, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, 40, 0A, 43, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, 90, F0, 42, 00, C9, C2, 08, 00, 8B, FF, 55, 8B, EC, 51, 53, 8B, 45, 0C, 83, C0, 0C, 89, 45, FC, 64, 8B, 1D, 00, 00, 00, 00, 8B, 03, 64, A3, 00, 00, 00, 00, 8B, 45, 08, 8B, 5D, 0C, 8B, 6D, FC, 8B, 63...
 
[+]

Entropy:
6.4104

Code size:
181.5 KB (185,856 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
PsmSvc

Command:
"C:\Program Files\lgcns\psm\agent\bin\crschksvc.exe"


Scan crschksvc.exe - Powered by Reason Core Security