utility.exe

Lenovo Battery Management Software Ver 6.0

Lenovo (Beijing) Limited

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘EnergyUtility’.
Publisher:
Lenovo(beijing) Limited  (signed by Lenovo (Beijing) Limited)

Product:
Lenovo Battery Management Software Ver 6.0

Version:
6, 0, 1, 6

MD5:
3290afb12d3a3d046eea876ed2f06977

SHA-1:
fa37aada898d59067518c93d27173343f8f1b42e

SHA-256:
bbb3d5ba01f7d876c54a24ec48edef9211b58c2ad31347872f200ca4131af1aa

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/10/2024 8:17:01 AM UTC  (today)

File size:
5.9 MB (6,236,064 bytes)

Product version:
6, 0, 1, 6

Copyright:
Lenovo(beijing) Limited All rights reserved.

Original file name:
utility.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\lenovo\energy management\utility.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
12/8/2009 5:30:00 AM

Valid to:
1/8/2012 5:29:59 AM

Subject:
CN=Lenovo (Beijing) Limited, OU=IT, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Lenovo (Beijing) Limited, L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2EDBA85021EE00C973B5C5398B2E1155

File PE Metadata
Compilation timestamp:
12/14/2010 7:55:47 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
12288:o+paDHmVIZ4snETX557lhp8xJz5VDB8jcGB8LS27SaOSikIlZLlWz1x:dcD9WTX5hSXB8jyKFZ581x

Entry address:
0x42511

Entry point:
E8, 62, 4C, 00, 00, E9, 17, FE, FF, FF, 55, 8B, EC, 56, 8B, 75, 14, 57, 33, FF, 3B, F7, 75, 04, 33, C0, EB, 65, 39, 7D, 08, 75, 1B, E8, 2D, 20, 00, 00, 6A, 16, 5E, 89, 30, 57, 57, 57, 57, 57, E8, CE, 17, 00, 00, 83, C4, 14, 8B, C6, EB, 45, 39, 7D, 10, 74, 16, 39, 75, 0C, 72, 11, 56, FF, 75, 10, FF, 75, 08, E8, AD, 10, 00, 00, 83, C4, 0C, EB, C1, FF, 75, 0C, 57, FF, 75, 08, E8, 7C, 04, 00, 00, 83, C4, 0C, 39, 7D, 10, 74, B6, 39, 75, 0C, 73, 0E, E8, DE, 1F, 00, 00, 6A, 22, 59, 89, 08, 8B, F1, EB, AD, 6A, 16...
 
[+]

Entropy:
5.6432

Code size:
364 KB (372,736 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
EnergyUtility

Command:
C:\Program Files\lenovo\energy management\utility.exe


Scan utility.exe - Powered by Reason Core Security