LenovoReg.exe

PowerReg

Leader Technologies Inc

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Lenovo Registration’.
Publisher:
Lenovo, Inc.  (signed by Leader Technologies Inc)

Product:
PowerReg

Description:
Lenovo Registration

Version:
1.0.4

MD5:
42fcc41c3062192bf93e729444e8216a

SHA-1:
13f3ad3ab769727805421f9e9eaa83870221a409

SHA-256:
2b2fdcb8098debf6e79935a39382045d5253dbdbf4b18a427c852a3426799437

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 7:15:35 PM UTC  (today)

File size:
4.2 MB (4,351,712 bytes)

Product version:
1.0.4

Copyright:
Copyright (C) 2011

Original file name:
LenovoReg.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\lenovo registration\lenovoreg.exe

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
6/17/2009 3:48:19 AM

Valid to:
7/9/2012 3:37:05 AM

Subject:
CN=Leader Technologies Inc, OU=Secure Application Development, O=Leader Technologies Inc, L=Albuquerque, S=New Mexico, C=US

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
406C28C26793D8B06A7F0651A73C7B78

File PE Metadata
Compilation timestamp:
7/14/2011 4:52:38 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
98304:BX4KHtoIXJmJSXVyk+4Axsb4LgO9TGxFOlBH1IIUX20iv8ND6hRPn2:BX4qtiAC9TIIBVIVND6hR

Entry address:
0x22477B

Entry point:
E8, A6, FA, 00, 00, E9, 89, FE, FF, FF, 3B, 0D, 00, A4, 76, 00, 75, 02, F3, C3, E9, 2D, FB, 00, 00, 8B, FF, 55, 8B, EC, FF, 75, 08, 51, E8, 95, FC, 00, 00, 59, 59, 5D, C2, 04, 00, 8B, FF, 51, C7, 01, 88, CC, 6D, 00, E8, 11, FC, 00, 00, 59, C3, 8B, FF, 55, 8B, EC, 56, 8B, F1, E8, E3, FF, FF, FF, F6, 45, 08, 01, 74, 07, 56, E8, 1A, BD, E5, FF, 59, 8B, C6, 5E, 5D, C2, 04, 00, 8B, FF, 55, 8B, EC, FF, 75, 08, 51, E8, E5, FD, 00, 00, 59, 59, 5D, C2, 04, 00, 8B, FF, 51, E8, 34, FD, 00, 00, 59, C3, 8B, FF, 55, 8B...
 
[+]

Entropy:
6.5634

Code size:
2.6 MB (2,770,432 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Lenovo Registration

Command:
C:\Program Files\lenovo registration\lenovoreg.exe \boot


Scan LenovoReg.exe - Powered by Reason Core Security