Energy Management.exe

Lenovo Energy Management Software 6.0

Lenovo (Beijing) Limited

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Energy Management’.
Publisher:
Lenovo (Beijing) Limited  (signed and verified)

Product:
Lenovo Energy Management Software 6.0

Version:
6, 0, 2, 0

MD5:
2f349d94b9862fa9c4333102c599712d

SHA-1:
8a3e80cc352b056ef3ad3a0eee23e4dec1674a6f

SHA-256:
1e19437f2baa09cc9ac5a4d06153f070d91ddfa82626eda08d47aae30fb29282

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/23/2024 9:45:16 PM UTC  (today)

File size:
9.3 MB (9,753,024 bytes)

Product version:
6, 0, 2, 0

Copyright:
Lenovo (Beijing) Limited。All Rights Reserved。

Original file name:
Energy Management.exe

File type:
Executable application (Win64 EXE)

Language:
Chinese (Simplified, China)

Common path:
C:\Program Files\lenovo\energy management\energy management.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
12/7/2009 4:00:00 PM

Valid to:
1/7/2012 3:59:59 PM

Subject:
CN=Lenovo (Beijing) Limited, OU=IT, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Lenovo (Beijing) Limited, L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2EDBA85021EE00C973B5C5398B2E1155

File PE Metadata
Compilation timestamp:
1/6/2011 6:49:44 PM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
8.0

Entry address:
0x183BE0

Entry point:
48, 83, EC, 28, E8, F7, 17, 01, 00, E8, 12, 00, 00, 00, 48, 83, C4, 28, C3, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 48, 81, EC, F8, 00, 00, 00, C7, 84, 24, B4, 00, 00, 00, 00, 00, 00, 00, C7, 84, 24, CC, 00, 00, 00, 00, 00, 00, 00, C7, 44, 24, 20, 00, 00, 00, 00, C7, 84, 24, C0, 00, 00, 00, 00, 00, 00, 00, C7, 84, 24, C4, 00, 00, 00, 00, 00, 00, 00, C7, 84, 24, C8, 00, 00, 00, 00, 00, 00, 00, 48, 8D, 4C, 24, 30, FF, 15, A7, FC, 04, 00, EB, 0A, B8, FF, 00, 00, 00, E9, B9, 02, 00, 00, FF, 15, 9D...
 
[+]

Entropy:
6.3400

Code size:
1.8 MB (1,907,712 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Energy Management

Command:
C:\Program Files\lenovo\energy management\energy management.exe


Scan Energy Management.exe - Powered by Reason Core Security