ldshell.exe

联想企业网盘

Lenovo (Beijing) Limited

It runs as a separate (within the context of its own process) windows Service named “MyLDShell”.
Publisher:
联想集团有限公司  (signed by Lenovo (Beijing) Limited)

Product:
联想企业网盘

Version:
3.0.0.41

MD5:
27e3248fd768e7170e1af7f117975101

SHA-1:
435115d4276f421c25b82ab4fa339daae59bb6df

SHA-256:
28cfc335f0b935c14c00a4d9c0f1cbccdcb13fbe36d14f60cffed38958dedff3

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
2/25/2025 8:38:44 AM UTC  (today)

File size:
272.7 KB (279,232 bytes)

Product version:
3.0.0.41

Copyright:
版权所有 2013 联想集团有限公司

Original file name:
MyLDShell.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\lenovo\lenovodata3\ldshell.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
3/19/2013 9:00:00 AM

Valid to:
4/19/2015 8:59:59 AM

Subject:
CN=Lenovo (Beijing) Limited, O=Lenovo (Beijing) Limited, L=Beijing, S=Beijing, C=CN

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
1B4F4F5F3E6EA9B04AAB02E43006E421

File PE Metadata
Compilation timestamp:
2/26/2014 5:56:15 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x9F7D

Entry point:
E8, 76, 4E, 00, 00, E9, 89, FE, FF, FF, 6A, 0C, 68, 78, 72, 41, 00, E8, FD, 3C, 00, 00, 6A, 0E, E8, 73, 50, 00, 00, 59, 83, 65, FC, 00, 8B, 75, 08, 8B, 4E, 04, 85, C9, 74, 2F, A1, 8C, A6, 41, 00, BA, 88, A6, 41, 00, 89, 45, E4, 85, C0, 74, 11, 39, 08, 75, 2C, 8B, 48, 04, 89, 4A, 04, 50, E8, 10, F6, FF, FF, 59, FF, 76, 04, E8, 07, F6, FF, FF, 59, 83, 66, 04, 00, C7, 45, FC, FE, FF, FF, FF, E8, 0A, 00, 00, 00, E8, EC, 3C, 00, 00, C3, 8B, D0, EB, C5, 6A, 0E, E8, 3F, 4F, 00, 00, 59, C3, CC, CC, CC, CC, CC, CC...
 
[+]

Entropy:
5.5746

Code size:
71.5 KB (73,216 bytes)

Service
Display name:
MyLDShell

Type:
Win32OwnProcess

Depends on:
RPCSS