itcurusr.exe

LIGHT STAR INFORMATION CO., LTD.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘SmartIT Client’.
Publisher:
Light Star Information  (signed by LIGHT STAR INFORMATION CO., LTD.)

Description:
SmartIT Client Current User

Version:
8

MD5:
0259b8d45cbf3611c75c7fb9218677ba

SHA-1:
0dbe97dde6c72fd7a3f8299a9eef263e1b1f656b

SHA-256:
c1c24abf93b9d096777b6f718db32170bd760b54e1c9fdd5988821c0f1254224

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 1:57:20 PM UTC  (today)

File size:
987.1 KB (1,010,840 bytes)

Copyright:
Copyright (c) Light Star Information 2012

Original file name:
lsass.exe

File type:
Executable application (Win32 EXE)

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/4/2010 8:00:00 AM

Valid to:
1/7/2013 7:59:59 AM

Subject:
CN="LIGHT STAR INFORMATION CO., LTD.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="LIGHT STAR INFORMATION CO., LTD.", L=Taipei, S=Taiwan, C=TW

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
616E97135B6E781B39D64B78AB3E8938

File PE Metadata
Compilation timestamp:
6/20/1992 6:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xD147C

Entry point:
55, 8B, EC, 83, C4, F0, B8, EC, 0D, 4D, 00, E8, 14, 5F, F3, FF, A1, 24, A0, 4D, 00, 8B, 00, E8, 50, BC, F8, FF, 8B, 0D, AC, 9E, 4D, 00, A1, 24, A0, 4D, 00, 8B, 00, 8B, 15, 3C, E4, 4C, 00, E8, 50, BC, F8, FF, A1, 24, A0, 4D, 00, 8B, 00, E8, C4, BC, F8, FF, E8, 27, 36, F3, FF, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.6587

Developed / compiled with:
Microsoft Visual C++

Code size:
833.5 KB (853,504 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
SmartIT Client

Command:
C:\smartit\itcurusr.exe


Scan itcurusr.exe - Powered by Reason Core Security