DpmLiteEvent.exe

Dell Power Manager Lite (Event)

Wistron Corporation

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘DpmLiteEvent’.
Publisher:
Wistron Corporation  (signed and verified)

Product:
Dell Power Manager Lite (Event)

Version:
1, 0, 1, 1119

MD5:
905f846e88b30bbd3ade29eb61652680

SHA-1:
186c5633fec78c0bbe105eca3b19f2103ea0af03

SHA-256:
8fe99cb9a259f1915551e80137da749f6d352bd01365174f9a28822bee3360e4

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 4:28:08 AM UTC  (today)

File size:
2.4 MB (2,537,776 bytes)

Product version:
1, 0, 1, 1119

Copyright:
Copyright (c) Wistron Corporation, 2014. All rights reserved.

Original file name:
DpmLiteEvent.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\dell\dpmlite\dpmliteevent.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/15/2012 5:00:00 PM

Valid to:
3/16/2015 4:59:59 PM

Subject:
CN=Wistron Corporation, OU=OS Certification Dept., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Wistron Corporation, L=Taipei, S=Taiwan, C=TW

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
397EABD0A3FCCD492184EF60AB31C8B8

File PE Metadata
Compilation timestamp:
11/19/2014 1:26:15 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x174EB0

Entry point:
48, 83, EC, 28, E8, 13, 7B, 00, 00, 48, 83, C4, 28, E9, 16, FE, FF, FF, CC, CC, 48, 89, 5C, 24, 08, 57, 48, 83, EC, 20, 48, 8D, 05, D3, 6F, 08, 00, 8B, DA, 48, 8B, F9, 48, 89, 01, E8, 9E, 7B, 00, 00, F6, C3, 01, 74, 08, 48, 8B, CF, E8, 21, 7C, E9, FF, 48, 8B, C7, 48, 8B, 5C, 24, 30, 48, 83, C4, 20, 5F, C3, CC, CC, CC, 48, 83, EC, 28, 48, 8B, C2, 48, 8D, 51, 11, 48, 8D, 48, 11, E8, FC, 7B, 00, 00, 33, C9, 3B, C1, 0F, 94, C0, 48, 83, C4, 28, C3, 48, 85, C9, 74, 37, 53, 48, 83, EC, 20, 4C, 8B, C1, 48, 8B, 0D...
 
[+]

Entropy:
6.1477

Code size:
1.7 MB (1,748,480 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
DpmLiteEvent

Command:
C:\Program Files\dell\dpmlite\dpmliteevent.exe


Scan DpmLiteEvent.exe - Powered by Reason Core Security