GiljabiStart.exe

LG LIU

LG Electronics Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘LG Intelligent Update’.
Publisher:
BIT LEADER  (signed by LG Electronics Inc.)

Product:
LG LIU

Description:
Giljabi Start

Version:
3.0.0.5

MD5:
4206260da168aac74e51fed8b0432f9e

SHA-1:
c0c44d3ff4438829b12d78d834d997efc93b03d8

SHA-256:
5f83141caa38897c35a120199e5d5d09c3290309f3f155fbbd4ec0567139f41a

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 10:33:32 AM UTC  (today)

File size:
241.3 KB (247,088 bytes)

Product version:
3.0.0.5

Copyright:
Copyright (C) 2006~2007

Original file name:
GiljabiStart.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\lg_swupdate\giljabistart.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
8/10/2007 2:00:00 AM

Valid to:
8/25/2008 1:59:59 AM

Subject:
CN=LG Electronics Inc., OU=Engineering Dept. DID Division, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=LG Electronics Inc., L=Kumi, S=Kyoungsangbuk-do, C=KR

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
103D387EAFDB9D10D9D61AEAF4A77090

File PE Metadata
Compilation timestamp:
9/14/2007 5:03:03 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:JOqjEAsCzO/rmihLqBVMZwqAt9onaLKQL3xQzZDo4QO0KysPjUocS3lVAWknV13Z:JOjJDLqAuqAt9onaLx+Qs3lVL8

Entry address:
0x39B6E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
224 KB (229,376 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
LG Intelligent Update

Command:
"C:\Program Files\lg_swupdate\giljabistart.exe" gilautouc