Energy Management.exe

Lenovo Energy Management Software

Lenovo (Beijing) Limited

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Energy Management’.
Publisher:
Lenovo (Beijing) Limited  (signed and verified)

Product:
Lenovo Energy Management Software

Version:
3, 1, 5, 8

MD5:
64267613881ddaf8b1b61eb9aa2df06d

SHA-1:
1c0dddfefee468dd3ec8c52fe6f9650552376114

SHA-256:
fe2e808650dc65352e1df2a0e8adb0ff057ad4839ecb2ccbddff5fcceae44644

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 11:51:05 AM UTC  (today)

File size:
8.4 MB (8,857,488 bytes)

Product version:
3, 1, 5, 8

Copyright:
Lenovo (Beijing) Limited。All Rights Reserved。

Original file name:
Energy Management.exe

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, PRC)

Common path:
C:\Program Files\lenovo\energy management\energy management.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/19/2007 6:00:00 PM

Valid to:
12/12/2008 5:59:59 PM

Subject:
CN=Lenovo (Beijing) Limited, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Lenovo (Beijing) Limited, L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
65EB539DC56EDE0AFFD971C59B620B57

File PE Metadata
Compilation timestamp:
8/4/2008 2:11:09 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

Entry address:
0x10A330

Entry point:
55, 8B, EC, E8, F8, C5, 00, 00, E8, 03, 00, 00, 00, 5D, C3, CC, 55, 8B, EC, 6A, FE, 68, D0, E7, 60, 00, 68, 00, 1B, 51, 00, 64, A1, 00, 00, 00, 00, 50, 81, C4, 78, FF, FF, FF, 53, 56, 57, A1, 4C, 73, 61, 00, 31, 45, F8, 33, C5, 50, 8D, 45, F0, 64, A3, 00, 00, 00, 00, 89, 65, E8, C7, 45, 88, 00, 00, 00, 00, C7, 85, 74, FF, FF, FF, 00, 00, 00, 00, C7, 45, E4, 00, 00, 00, 00, C7, 45, 80, 00, 00, 00, 00, C7, 85, 7C, FF, FF, FF, 00, 00, 00, 00, C7, 85, 78, FF, FF, FF, 00, 00, 00, 00, C7, 45, FC, 00, 00, 00, 00...
 
[+]

Entropy:
7.0856

Developed / compiled with:
Microsoft Visual C++

Code size:
1.3 MB (1,372,160 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Energy Management

Command:
"C:\Program Files\lenovo\energy management\energy management.exe"