SetPsave.exe

Power Saving Utility

Matsushita Electric Industrial Co., Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘SetPsave’.
Publisher:

Product:
Power Saving Utility

Version:
4, 2, 1000, 0

MD5:
6a3a9c214947198fd4198863afe5e013

SHA-1:
cefa1a41638c2b121a6809727dc1ccf699a17bd4

SHA-256:
48efd5c1682e796cdf1787441afd26f5a803e34721543b5807233c1a3ce691b2

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 7:43:50 AM UTC  (today)

File size:
593.4 KB (607,592 bytes)

Product version:
V4.02L10 M00

Copyright:
(C) 2005-2008 Matsushita Electric Industrial Co., Ltd.

Trademarks:
Panasonic

Original file name:
SetPsave.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\panasonic\setpsave\setpsave.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/27/2007 9:00:00 AM

Valid to:
11/27/2008 8:59:59 AM

Subject:
CN="Matsushita Electric Industrial Co., Ltd.", OU="IT Products Division, Panasonic AVC Netwroks Company", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Matsushita Electric Industrial Co., Ltd.", L=Moriguchi, S=Osaka, C=JP

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
56BC57AC9C0BA5DB6C2CD5273D89E882

File PE Metadata
Compilation timestamp:
3/7/2008 4:27:58 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:NMBJzeq1sIV/+i2bMZKOrWTdK7axkmVkz7Kq1QleVfdWdt7W4/FOQcudijxI8Wb+:uBJzeq1/2oZKi+vxkmVgqksa

Entry address:
0xF3CD

Entry point:
E8, 6B, 5C, 00, 00, E9, 17, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, 55, 8B, EC, 57, 56, 8B, 75, 0C, 8B, 4D, 10, 8B, 7D, 08, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, A4, 01, 00, 00, 81, F9, 00, 01, 00, 00, 72, 1F, 83, 3D, 5C, 8E, 42, 00, 00, 74, 16, 57, 56, 83, E7, 0F, 83, E6, 0F, 3B, FE, 5E, 5F, 75, 08, 5E, 5F, 5D, E9, 31, 5D, 00, 00, F7, C7, 03, 00, 00, 00, 75, 15, C1, E9, 02, 83, E2, 03, 83, F9, 08, 72, 2A, F3, A5, FF, 24, 95, 54, F5, 40, 00, 90, 8B, C7, BA, 03, 00, 00, 00, 83, E9...
 
[+]

Entropy:
4.9154

Code size:
112 KB (114,688 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
SetPsave

Command:
"C:\Program Files\panasonic\setpsave\setpsave.exe" \etm


Scan SetPsave.exe - Powered by Reason Core Security