mainserv.exe

PowerChute Personal Edition

American Power Conversion

It runs as a separate (within the context of its own process) windows Service named “APC UPS Service”.
Publisher:
Schneider Electric  (signed by American Power Conversion)

Product:
PowerChute Personal Edition

Description:
Battery Backup Management Service

Version:
3.0.1.0

MD5:
4e074858699db7623e37858e62fd5fe3

SHA-1:
ba9081aac6be7d3491f1404c7de6588a2ca1095b

SHA-256:
3b9fc32c70f3fe0c63527416d76981b0ce3fa65e99954c2625e6d368274f21fa

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 3:53:49 AM UTC  (today)

File size:
689.4 KB (705,912 bytes)

Product version:
3.0.1.0

Copyright:
Copyright © 2002-2011 Schneider Electric

Original file name:
PowerChute

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\apc\powerchute personal edition\mainserv.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/20/2010 8:00:00 PM

Valid to:
5/4/2012 7:59:59 PM

Subject:
CN=American Power Conversion, OU=132 Fairgrounds Rd, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=American Power Conversion, L=West Kingston, S=Rhode Island, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0DAAB5D95410B6338FE16346FEAC7AD5

File PE Metadata
Compilation timestamp:
7/1/2011 9:56:57 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
12288:k1qsNzMU7jkvBhU6s4g5PKs0Rr72FR9ozuCmSuYS:kVN2C4iyTRr79qYS

Entry address:
0x40784

Entry point:
E9, BD, 96, 04, 00, E9, B3, 19, 02, 00, E9, 84, 9F, 02, 00, E9, 21, 7F, 02, 00, E9, 9F, 2F, 02, 00, E9, 9D, 18, 02, 00, E9, D9, 23, 03, 00, E9, 37, 0A, 02, 00, E9, F1, E0, 01, 00, E9, 4A, 84, 01, 00, E9, 2B, 8B, 07, 00, E9, 22, 89, 07, 00, E9, F2, 51, 03, 00, E9, 28, 38, 02, 00, E9, 13, 0E, 02, 00, E9, F6, 0D, 02, 00, E9, 97, 3B, 01, 00, E9, 50, 85, 07, 00, E9, 1E, 0F, 06, 00, E9, C1, 16, 02, 00, E9, 82, FC, 01, 00, E9, 15, B8, 02, 00, E9, 49, 2A, 01, 00, E9, 4C, 8C, 07, 00, E9, 87, 95, 03, 00, E9, C1, 4B...
 
[+]

Entropy:
5.7468

Developed / compiled with:
Microsoft Visual C++ 8.0 (Debug)

Code size:
548 KB (561,152 bytes)

Service
Display name:
APC UPS Service

Description:
PowerChute Personal Edition service for managing battery backup power events.

Type:
Win32OwnProcess