keyremapper.exe

ATNSOFT Key Remapper

ATNSOFT

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘ATNSOFT Key Remapper’.
Publisher:
ATNSOFT  (signed and verified)

Product:
ATNSOFT Key Remapper

Version:
1.6.0.364

MD5:
6e63342019dcde6fb8725c9875682ee3

SHA-1:
c13a0c1ceb918b07170d34368f78e6ce0103106a

SHA-256:
b52c8c11dd1e28e8710350644bc102d91718900ce3ea5204744c164888517eb6

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/23/2024 4:39:36 PM UTC  (today)

File size:
1.8 MB (1,913,744 bytes)

Product version:
1.6.0.364

Copyright:
Copyright (c) 2008-2013 ATNSOFT. All rights reserved.

Original file name:
keyremapper.exe

File type:
Executable application (Win32 EXE)

Language:
Russian (Russia)

Common path:
C:\Program Files\atnsoft key remapper\keyremapper.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
11/15/2012 1:00:00 AM

Valid to:
11/16/2013 12:59:59 AM

Subject:
CN=ATNSOFT, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=ATNSOFT, L=Lipetsk, S=Russia, C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
70B0CB0E8DEA6D05266C76B7A6479C35

File PE Metadata
Compilation timestamp:
1/5/2013 10:23:08 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:YH6TJDT1Pu/zuaBA1LnmD233ZdYotcQXkkWdUN:YH6T9T1Pu/zuFtnmD2ZqotpXOdI

Entry address:
0x4361EA

Entry point:
E8, 3B, FF, FF, FF, 05, F3, BC, 00, 00, FF, E0, E8, 2F, FF, FF, FF, 05, 86, 60, 00, 00, FF, E0, E8, 04, 00, 00, 00, FF, FF, FF, FF, 5E, C3, 00, 06, FC, DE, B5, D4, 00, 89, 15, 22, 39, 6E, 50, A9, 96, C2, 0E, 5D, 36, 47, BE, 07, 79, F6, AD, 27, F8, 6D, 45, 1F, 46, 1B, 62, 34, 4E, 6B, 38, 58, 39, C3, 3F, D4, 64, BC, 15, 94, 84, 2C, 2F, C5, FA, 48, 10, 3F, 79, 65, B7, 34, F3, D8, 45, 43, FE, 96, 0C, FC, 8D, 8A, AD, 65, 4A, 36, AB, 32, A9, C8, 8D, 7C, 6F, 39, A2, 28, A7, 21, E1, 89, 39, F4, CE, 63, 7D, 9E, C3...
 
[+]

Entropy:
7.1516

Code size:
1.2 MB (1,272,832 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
ATNSOFT Key Remapper

Command:
"C:\Program Files\atnsoft key remapper\keyremapper.exe" \startup


Scan keyremapper.exe - Powered by Reason Core Security