utility.exe

Lenovo Battery Management Software Ver 6.0

Lenovo (Beijing) Limited

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘EnergyUtility’.
Publisher:
Lenovo(beijing) Limited  (signed by Lenovo (Beijing) Limited)

Product:
Lenovo Battery Management Software Ver 6.0

Version:
6, 0, 0, 7

MD5:
3cbb3d8778a03867848268cf0c1094fa

SHA-1:
aa142ff6256edadbff74e0534ca796679eaef4d7

SHA-256:
5c7d1623ccb2e567747577513ec79cb4b2ad5a3d7efafbca08e2847e255dfd6b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/16/2024 6:48:55 PM UTC  (today)

File size:
4.8 MB (5,044,128 bytes)

Product version:
6, 0, 0, 7

Copyright:
Lenovo(beijing) Limited All rights reserved.

Original file name:
utility.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\lenovo\energy management\utility.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
12/8/2009 1:00:00 AM

Valid to:
1/8/2012 12:59:59 AM

Subject:
CN=Lenovo (Beijing) Limited, OU=IT, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Lenovo (Beijing) Limited, L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2EDBA85021EE00C973B5C5398B2E1155

File PE Metadata
Compilation timestamp:
10/21/2010 12:40:05 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
12288:1hntcDMe4SClzkYDDZIp1nv5AF/mWtWT+x/9CaVWiWDymU75zFVlH6Cox7zBydBq:N15Rc1nhAxncBSB8jyWZ5q6KHy

Entry address:
0x44410

Entry point:
E8, E3, 4C, 00, 00, E9, 17, FE, FF, FF, 51, C7, 01, 40, 69, 46, 00, E8, 66, 4D, 00, 00, 59, C3, 56, 8B, F1, E8, EA, FF, FF, FF, F6, 44, 24, 08, 01, 74, 07, 56, E8, B3, 03, FE, FF, 59, 8B, C6, 5E, C2, 04, 00, 8B, 44, 24, 04, 83, C1, 09, 51, 83, C0, 09, 50, E8, AB, 4D, 00, 00, F7, D8, 59, 1B, C0, 59, 40, C2, 04, 00, 3B, 0D, 9C, 5B, 47, 00, 75, 02, F3, C3, E9, 1A, 4E, 00, 00, 55, 8B, EC, 51, 53, 8B, 45, 0C, 83, C0, 0C, 89, 45, FC, 64, 8B, 1D, 00, 00, 00, 00, 8B, 03, 64, A3, 00, 00, 00, 00, 8B, 45, 08, 8B, 5D...
 
[+]

Code size:
372 KB (380,928 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
EnergyUtility

Command:
C:\Program Files\lenovo\energy management\utility.exe