keyremapper.exe

ATNSOFT Key Remapper

ATNSOFT

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘ATNSOFT Key Remapper’.
Publisher:
ATNSOFT  (signed and verified)

Product:
ATNSOFT Key Remapper

Version:
1.10.0.416

MD5:
e24e2542e4304b6c86de25295d7cb11f

SHA-1:
2709cfffc0e5257aa345d0a048a5909436145142

SHA-256:
fa1a28fa40b5fc93e9589a09c95335213f391888213e6259f67ace851f8b718e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/31/2024 11:07:25 PM UTC  (a few moments ago)

File size:
2.2 MB (2,291,672 bytes)

Product version:
1.10.0.416

Copyright:
Copyright © 2008-2016 ATNSOFT. All rights reserved.

Original file name:
keyremapper.exe

File type:
Executable application (Win32 EXE)

Language:
Russian (Russia)

Common path:
C:\Program Files\atnsoft key remapper\keyremapper.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
11/23/2016 10:00:00 PM

Valid to:
12/24/2019 9:59:59 PM

Subject:
CN=ATNSOFT, O=ATNSOFT, L=Lipetsk, S=Russia, C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
369DB8D34CE5BF398A25F07EC13E430D

File PE Metadata
Compilation timestamp:
3/5/2013 4:41:23 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:bH6TJDTmnB+250V9vlPs6r3kKKMPEM+CBpRs:bH6T9TmnB+Q0vua05OEya

Entry address:
0x49836A

Entry point:
E8, 3B, FF, FF, FF, 05, 82, B9, 00, 00, FF, E0, E8, 2F, FF, FF, FF, 05, B3, B7, 00, 00, FF, E0, E8, 04, 00, 00, 00, FF, FF, FF, FF, 5E, C3, 00, 92, 82, BE, 06, AF, 23, 1F, 40, D2, 04, 9B, 17, 0D, C3, EB, 77, F1, 87, EE, 79, 84, 7F, 82, 68, 19, 4D, 4A, F4, 00, 72, 9F, 0E, 6A, 25, 69, 18, 0D, 01, 9D, 7A, 2F, 91, 34, 83, DB, 0A, 28, 0E, 97, 30, A4, 0C, F1, 39, FD, AF, 2A, A9, D6, 8B, 4A, 8E, AB, A9, D2, B7, A3, 42, F2, 47, D4, BD, 46, 0D, 07, E2, 5C, A6, 5C, 01, 70, 96, A0, 25, A2, F9, A1, 4B, 07, 59, 91, 32...
 
[+]

Code size:
1.2 MB (1,282,048 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
ATNSOFT Key Remapper

Command:
"C:\Program Files\atnsoft key remapper\keyremapper.exe" \startup


Scan keyremapper.exe - Powered by Reason Core Security