PopWnd.exe

Lenovo EE Boot Optimizer Software

Lenovo (Beijing) Limited

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Lenovo EE Boot Optimizer’.
Publisher:
Lenovo  (signed by Lenovo (Beijing) Limited)

Product:
Lenovo EE Boot Optimizer Software

Version:
0, 0, 1, 4

MD5:
33aba19010bb95771de4cd58232924cf

SHA-1:
28e6af38839960a38ef672a2b0d397c8c8ac0a53

SHA-256:
cf40fa2ad8ee77d8ad634b80bb715677c9c93ec3c29957951d835dba236002ed

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 10:44:28 PM UTC  (today)

File size:
201.3 KB (206,176 bytes)

Product version:
0, 0, 1, 4

Copyright:
Lenovo Copyright (C) 2010

Original file name:
PopWnd.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\lenovo\boot optimizer\popwnd.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
12/8/2009 5:30:00 AM

Valid to:
1/8/2012 5:29:59 AM

Subject:
CN=Lenovo (Beijing) Limited, OU=IT, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Lenovo (Beijing) Limited, L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2EDBA85021EE00C973B5C5398B2E1155

File PE Metadata
Compilation timestamp:
1/28/2011 9:24:34 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

Entry address:
0x1162C

Entry point:
E9, 4F, A4, 00, 00, E9, DC, B2, 00, 00, E9, C5, 06, 00, 00, E9, EA, A0, 00, 00, E9, 73, C1, 00, 00, E9, F2, C7, 00, 00, E9, 81, AC, 00, 00, E9, 96, A1, 00, 00, E9, 37, B5, 00, 00, E9, 10, A2, 00, 00, E9, 2B, C7, 00, 00, E9, C8, BF, 00, 00, E9, 57, AC, 00, 00, E9, 14, 9F, 00, 00, E9, CB, A0, 00, 00, E9, F6, C7, 00, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC...
 
[+]

Entropy:
4.8806

Developed / compiled with:
Microsoft Visual C++ 8.0 (Debug)

Code size:
68 KB (69,632 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Lenovo EE Boot Optimizer

Command:
C:\Program Files\lenovo\boot optimizer\popwnd.exe


Scan PopWnd.exe - Powered by Reason Core Security