i-atm.exe

I-ATM SmartCard Service

InfoThink Technology Co., LTD.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘I-ATM’.
Publisher:
InfoThink Technology CO., LTD.  (signed by InfoThink Technology Co., LTD.)

Product:
I-ATM SmartCard Service

Description:
I-ATM SmartCard Application

Version:
3.4.2.0

MD5:
dca65c4589e336f5ca896498d09a80a8

SHA-1:
8b237014d857337a7f53a5b7463aad21ea0ccf91

SHA-256:
9473b1f5ee3c8d281f9c3fea900298c45acd8cb45d1e5629537e19af52b56807

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/25/2024 6:04:21 AM UTC  (today)

File size:
829.5 KB (849,448 bytes)

Product version:
3.4.2.0

Copyright:
Copyright (c) InfoThink. 2003 - 2015

Original file name:
i-atm.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\it\i-atm\i-atm.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
3/5/2013 8:00:00 AM

Valid to:
3/5/2016 7:59:59 AM

Subject:
CN="InfoThink Technology Co., LTD.", OU=I-TRAVEL, O="InfoThink Technology Co., LTD.", STREET="7F-1., No.510, Sec. 5, Zhongxiao E. Rd., Xinyi District, Taipei City 11083, Taiwan(R.O.C.)", L=Taipei City, S=Taipei, PostalCode=11077, C=TW

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
756DA513E4C4AA0E05AACBB13CFAEB33

File PE Metadata
Compilation timestamp:
10/5/2015 2:18:28 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:L9AlFlluqMLnxc51GFfC+Ch4fuhGQluv8tBtPqIOgGpWolWXNnXbeiU1gq0XgcnJ:RdnTfC+qbh58WolIA0QcnqccV7wDh

Entry address:
0x4A1EC

Entry point:
E8, 6D, 83, 00, 00, E9, 16, FE, FF, FF, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 44, 13, 47, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 44, 13, 47, 00, 33, C5, 50, 89, 65, F0, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B...
 
[+]

Entropy:
6.9382

Code size:
360 KB (368,640 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
I-ATM

Command:
C:\Program Files\it\i-atm\i-atm.exe


Scan i-atm.exe - Powered by Reason Core Security