keyremapper.exe

ATNSOFT Key Remapper

ATNSOFT

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘ATNSOFT Key Remapper’.
Publisher:
ATNSOFT  (signed and verified)

Product:
ATNSOFT Key Remapper

Version:
1.9.0.400

MD5:
8b6b4946f411b8574497564d72108aac

SHA-1:
8c2f1f0b1a27f6800fbff6ab1b8a792cf40dd84e

SHA-256:
3fb0e1eec047f1f0fc1fa6b8e73bb0929af1c4dee56aae1f3ed02587655c6009

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/29/2024 5:32:32 AM UTC  (today)

File size:
2.2 MB (2,277,112 bytes)

Product version:
1.9.0.400

Copyright:
Copyright © 2008-2015 ATNSOFT. All rights reserved.

Original file name:
keyremapper.exe

File type:
Executable application (Win32 EXE)

Language:
Russian (Russia)

Common path:
C:\Program Files\atnsoft key remapper\keyremapper.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
11/1/2013 4:00:00 PM

Valid to:
12/1/2016 3:59:59 PM

Subject:
CN=ATNSOFT, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=ATNSOFT, L=Lipetsk, S=Russia, C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7586760122385888546CB1A4905819B2

File PE Metadata
Compilation timestamp:
11/11/2013 9:36:46 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:gH6TJDTmnB+2GEspvNIIqXHJwp8jv1uJkNuHY9rZI4:gH6T9TmnB+UszypwmYeqqr/

Entry address:
0x4945DC

Entry point:
E8, 3B, FF, FF, FF, 05, A2, 50, 00, 00, FF, E0, E8, 2F, FF, FF, FF, 05, 21, 3D, 00, 00, FF, E0, E8, 04, 00, 00, 00, FF, FF, FF, FF, 5E, C3, 00, 4C, A7, 75, 61, 00, 5D, 11, DB, 57, D4, 9A, E5, 83, 31, 4A, B6, 71, 9D, 20, 9B, D5, 1D, 14, 15, 36, 60, 0A, 37, C7, 0F, 82, 91, 75, 2C, F6, E0, B0, 73, 5F, B8, 64, 00, 8B, 90, 1C, 6A, 67, 7E, 45, 84, 12, E0, 5D, DE, 44, DA, A0, B4, 96, EB, E7, 1E, 64, 15, 61, 76, E4, 05, E4, CD, 5B, A6, 51, B8, 8A, 3E, 41, 4D, FD, CB, 27, 23, 3A, 4D, 1C, E2, CA, 58, 3B, 3E, DA, DB...
 
[+]

Entropy:
6.8115

Code size:
1.2 MB (1,281,536 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
ATNSOFT Key Remapper

Command:
"C:\Program Files\atnsoft key remapper\keyremapper.exe" \startup


Scan keyremapper.exe - Powered by Reason Core Security