File details
File name: awaysch.exe
Name: Away Manager
Description: Away Scheduler
Version: 2, 0, 5, 1
Size: 68 KB
Original file name: AWAYSCH.EXE
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0000325356%
Privileged CPU:
0.0000220920%

User CPU:
0.00001044360785%

Privileged CPU time: 307.29 ms
Privileged CPU time /min: 0 ms
 | Memory utilization averages |
Committed memory:
25.29 MB
Peak committed memory: 30.89 MB
Paged memory:
1.27 MB
Peak paged memory: 1.43 MB
Paged system memory:
40.28 KB
Non-paged system memory: 2.29 KB
Working set memory:
2.45 MB
Peak working set memory: 3.4 MB
Min working set memory: 2.42 MB
Private memory:
1.27 MB
Page faults:
1,390
Page faults /min: 1
 | Process I/O averages |
Total read operations:
42
Read operations /min: 1
Total read transfer: 65.68 KB
Read transfer /min: 32 Bytes
Total write operations:
20
Write operations /min: 1
Total write transfer: 13.13 KB
Write transfer /min: 6 Bytes
Total other operations:
516
Other operations /min: 1
Total other transfer: 41.21 KB
Other Transfer /min: 36 Bytes
 | GUI Object Averages |
GDI objects:
9
USER objects:
3
Resources
Handle count average: 49
Thread count average: 3
Thread resource averages
Total CPU: 0.000029196095%
Privileged CPU: 0.000018119260%
User CPU: 0.000011076835%
Module memory size: 76 KB
Process details
Runs as (owner): User
Integrety level: Undefined
Windows platform: 32-bit
Parent Processes
Process Command
"C:\Program Files\Lenovo\AwayTask\AwaySch.EXE"
Startup files (all users) run details
Name: AwaySch
Command: "C:\Program Files\Lenovo\AwayTask\AwaySch.EXE"
Image hashes
MD5: 3160bb9a01e5d430b338fb932a919c50
SHA-1: 8cdc18a4f5aaa6e64d59527d2286ed32587f602d
SHA-256: 3828056efef84d5e98622288894a059d0f93b4d8cf9e2da8d12374287c712c8f
PE image details
Subsystem: Windows GUI
File packed: No
Import Table
advapi32.dll

GetUserNameW
RegCloseKey
RegOpenKeyExW
RegQueryValueExW
awayapi.dll

_awProcDBWritePrivateProfileStringW@16
kernel32.dll

LoadLibraryA
GetProcAddress
HeapReAlloc
VirtualAlloc
GetOEMCP
GetACP
CloseHandle
GetLastError
CreateMutexA
WaitForMultipleObjects
ResetEvent
CreateEventW
lstrcpyW
lstrlenW
GetPrivateProfileStringW
SetEvent
SystemTimeToTzSpecificLocalTime
GetSystemTime
FileTimeToSystemTime
CompareFileTime
SystemTimeToFileTime
LoadLibraryW
GetStringTypeA
lstrcmpW
ReleaseMutex
CreateMutexW
CreateProcessW
TerminateProcess
WaitForSingleObject
CreateEventA
GetSystemDirectoryA
HeapAlloc
GetProcessHeap
HeapFree
GetCPInfo
SetFilePointer
WriteFile
RtlUnwind
VirtualFree
HeapCreate
HeapDestroy
GetVersionExA
GetVersion
GetEnvironmentVariableA
GetFileType
GetStdHandle
SetHandleCount
GetEnvironmentStringsW
GetEnvironmentStrings
FreeEnvironmentStringsW
GetStringTypeW
SetStdHandle
LCMapStringA
LCMapStringW
ReadFile
ExitProcess
GetCurrentProcess
UnhandledExceptionFilter
GetModuleFileNameA
GetUserDefaultLangID
FlushFileBuffers
WideCharToMultiByte
MultiByteToWideChar
GetModuleHandleA
GetStartupInfoA
GetCommandLineA
FreeEnvironmentStringsA
prochlp.dll

PH_GetOSVersion
PH_GetVersion
PH_CleanupThread
PH_InitializeThread
rpcrt4.dll

NdrServerCall2
RpcEpUnregister
RpcMgmtWaitServerListen
RpcServerListen
RpcServerRegisterAuthInfoA
RpcEpRegisterA
RpcServerInqBindings
RpcServerRegisterIf
RpcServerUseProtseqA
RpcServerUnregisterIf
RpcMgmtStopServerListening
RpcBindingVectorFree
user32.dll

TranslateAcceleratorA
DispatchMessageA
GetMessageA
LoadAcceleratorsA
LoadStringA
RegisterClassExA
LoadCursorA
CreateWindowExA
PostQuitMessage
DefWindowProcA
wsprintfW
MessageBoxW
LoadStringW
TranslateMessage
LoadIconA