itcurusr.exe

LIGHT STAR INFORMATION CO., LTD.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘SmartIT Client’.
Publisher:
Light Star Information  (signed by LIGHT STAR INFORMATION CO., LTD.)

Description:
SmartIT Client Current User

Version:
7

MD5:
9a887615648ee34e02d726466a088cef

SHA-1:
1d4a285306cf958f4bb4576a3439ad375499c9fa

SHA-256:
6ee072bcb77818066c540dfadf379c2c60a1c3ce8e4b8e27c259abc7f198c8ae

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/10/2024 8:10:02 AM UTC  (today)

File size:
961.1 KB (984,216 bytes)

Copyright:
Copyright (c) Light Star Information 2010

Original file name:
lsass.exe

File type:
Executable application (Win32 EXE)

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/4/2010 8:00:00 AM

Valid to:
1/7/2013 7:59:59 AM

Subject:
CN="LIGHT STAR INFORMATION CO., LTD.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="LIGHT STAR INFORMATION CO., LTD.", L=Taipei, S=Taiwan, C=TW

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
616E97135B6E781B39D64B78AB3E8938

File PE Metadata
Compilation timestamp:
6/20/1992 6:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:kcI11MWUgtGcY+EWO9WmQimKucJjkvjjZ15hGDY7TU+nDk7:kcAUEGcY5WR/cJjkbjZ15h0UTPnDk7

Entry address:
0xCB2E8

Entry point:
55, 8B, EC, 83, C4, F0, B8, 88, AC, 4C, 00, E8, A4, C0, F3, FF, A1, 08, 40, 4D, 00, 8B, 00, E8, E0, 2B, F9, FF, 8B, 0D, 94, 3E, 4D, 00, A1, 08, 40, 4D, 00, 8B, 00, 8B, 15, 70, 89, 4C, 00, E8, E0, 2B, F9, FF, A1, 08, 40, 4D, 00, 8B, 00, E8, 54, 2C, F9, FF, E8, B7, 97, F3, FF, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.6466

Developed / compiled with:
Microsoft Visual C++

Code size:
809 KB (828,416 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
SmartIT Client

Command:
C:\smartit\itcurusr.exe


Scan itcurusr.exe - Powered by Reason Core Security