utility.exe

Lenovo Battery Management Software Ver 6.0

Lenovo (Beijing) Limited

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘EnergyUtility’.
Publisher:
Lenovo(beijing) Limited  (signed by Lenovo (Beijing) Limited)

Product:
Lenovo Battery Management Software Ver 6.0

Version:
6, 0, 2, 0

MD5:
f7404794f6c9c8ea0b9443d31e696dbf

SHA-1:
9d2950c271ada2d1cc4d9ccc7992db289868e51a

SHA-256:
e79c50f6ea022aa41a502d780cb72232ac094fd008c31edc51a1f58ef00b1f08

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 2:43:07 AM UTC  (today)

File size:
5.6 MB (5,908,928 bytes)

Product version:
6, 0, 2, 0

Copyright:
Lenovo(beijing) Limited All rights reserved.

Original file name:
utility.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\lenovo\energy management\utility.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
12/8/2009 1:00:00 AM

Valid to:
1/8/2012 12:59:59 AM

Subject:
CN=Lenovo (Beijing) Limited, OU=IT, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Lenovo (Beijing) Limited, L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2EDBA85021EE00C973B5C5398B2E1155

File PE Metadata
Compilation timestamp:
1/7/2011 3:50:36 AM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
8.0

Entry address:
0x61A40

Entry point:
48, 83, EC, 28, E8, 77, 6E, 00, 00, 48, 83, C4, 28, E9, 0E, FD, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 48, 83, EC, 38, 4D, 85, C9, 48, 89, 5C, 24, 48, 48, 89, 74, 24, 50, 48, 89, 7C, 24, 58, 49, 8B, D9, 49, 8B, F0, 48, 8B, FA, 74, 56, 48, 85, C9, 75, 3C, E8, 35, 32, 00, 00, 45, 33, C9, 45, 33, C0, 33, D2, 33, C9, 48, C7, 44, 24, 20, 00, 00, 00, 00, C7, 00, 16, 00, 00, 00, E8, 57, 24, 00, 00, B8, 16, 00, 00, 00, 48, 8B, 7C, 24, 58, 48, 8B, 74, 24, 50, 48, 8B, 5C, 24, 48, 48, 83, C4...
 
[+]

Entropy:
6.3464

Code size:
512.5 KB (524,800 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
EnergyUtility

Command:
C:\Program Files\lenovo\energy management\utility.exe