keyremapper.exe

ATNSOFT Key Remapper

ATNSOFT

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘ATNSOFT Key Remapper’.
Publisher:
ATNSOFT  (signed and verified)

Product:
ATNSOFT Key Remapper

Version:
1.6.0.370

MD5:
73c510a176925ea391f1027a8b70b613

SHA-1:
fd0a058e7eb6cbc2bbe22e2c084c00d0939f3237

SHA-256:
200ad46ad8fb7641c00ff03fbc482df8e54b1d3313a8b5fd26d4c511a2d1536b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/31/2024 11:18:19 PM UTC  (a few moments ago)

File size:
1.8 MB (1,917,176 bytes)

Product version:
1.6.0.370

Copyright:
Copyright (c) 2008-2013 ATNSOFT. All rights reserved.

Original file name:
keyremapper.exe

File type:
Executable application (Win32 EXE)

Language:
Russian (Russia)

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
11/15/2012 1:00:00 AM

Valid to:
11/16/2013 12:59:59 AM

Subject:
CN=ATNSOFT, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=ATNSOFT, L=Lipetsk, S=Russia, C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
70B0CB0E8DEA6D05266C76B7A6479C35

File PE Metadata
Compilation timestamp:
1/10/2013 2:50:02 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:RH6TJDT1doTkZG6dUcpXo9V4fVtf7CUkYzD+:RH6T9T1doTk3UcFYKVtf7CUT+

Entry address:
0x43815B

Entry point:
E8, 3B, FF, FF, FF, 05, B2, 9E, 00, 00, FF, E0, E8, 2F, FF, FF, FF, 05, DA, 7B, 00, 00, FF, E0, E8, 04, 00, 00, 00, FF, FF, FF, FF, 5E, C3, 00, D6, AA, 0C, 34, 0E, 94, 76, 63, 2A, 6C, CB, 06, 14, B5, 36, F7, 03, 49, 4C, 02, 4D, 2D, E7, F0, 7F, 49, 81, FD, 98, BB, 80, A5, 44, 4D, A5, E6, D6, 0C, D7, 16, 01, D7, 01, EA, 98, 50, EA, C5, 57, 0A, 38, A9, F2, EF, 24, 2B, D3, C8, 0C, 85, CD, E3, 44, 1A, 8B, E2, FF, 57, 8E, B0, 6B, D0, 07, F7, F0, 12, 0D, BB, CC, 16, 18, FA, DF, 45, B1, 70, 72, 02, 48, 10, 73, D4...
 
[+]

Entropy:
7.1520

Code size:
1.2 MB (1,272,832 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
ATNSOFT Key Remapper

Command:
"C:\new folder\new folder\atnsoft key remapper\keyremapper.exe" \startup


Scan keyremapper.exe - Powered by Reason Core Security