keyremapper.exe

ATNSOFT Key Remapper

ATNSOFT

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘ATNSOFT Key Remapper’.
Publisher:
ATNSOFT  (signed and verified)

Product:
ATNSOFT Key Remapper

Version:
1.7.0.377

MD5:
a8c2cc5402dc97b1aa67fd17e4f29d61

SHA-1:
edebc40b521a56dd68fd00ea68973ed7ba845303

SHA-256:
56c83e3c5d3b6b8efcbe2792c0d2dffea16352d11a87ee6bcc8220b78eb58c5c

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/10/2024 11:50:56 PM UTC  (a few moments ago)

File size:
1.8 MB (1,920,760 bytes)

Product version:
1.7.0.377

Copyright:
Copyright (c) 2008-2013 ATNSOFT. All rights reserved.

Original file name:
keyremapper.exe

File type:
Executable application (Win32 EXE)

Language:
Russian (Russia)

Common path:
C:\Program Files\atnsoft key remapper\keyremapper.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
11/1/2013 10:00:00 PM

Valid to:
12/1/2016 9:59:59 PM

Subject:
CN=ATNSOFT, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=ATNSOFT, L=Lipetsk, S=Russia, C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7586760122385888546CB1A4905819B2

File PE Metadata
Compilation timestamp:
11/21/2013 11:03:30 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:dH6TJDT1n1BlKcZGgEr81lZDXIzykTzrjsKV:dH6T9T11DHM+tXZAYKV

Entry address:
0x43DD6D

Entry point:
E8, 3B, FF, FF, FF, 05, 44, 45, 00, 00, FF, E0, E8, 2F, FF, FF, FF, 05, C7, 5C, 00, 00, FF, E0, E8, 04, 00, 00, 00, FF, FF, FF, FF, 5E, C3, 00, 2F, EA, 33, 1F, C9, E6, 04, 01, 0C, 2D, 83, 6A, AD, 2F, AC, F6, 2F, A4, 7E, 56, 2B, 0C, B9, ED, B5, B6, B1, B1, 37, 6F, 23, 4F, E2, 61, C3, 09, 95, C0, CB, 30, 13, AF, F5, 1A, 34, 1C, 47, 8E, E5, C5, DD, FA, 07, AD, E8, 4C, 93, 39, DC, 8E, 78, 6F, 0F, 58, 55, 5B, CC, 1C, 37, 7D, 76, 25, 5B, 59, D7, 1B, 52, 44, CC, BB, 9B, 7B, 75, 2C, 93, C5, 27, 52, C8, E6, 2F, AD...
 
[+]

Code size:
1.2 MB (1,276,416 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
ATNSOFT Key Remapper

Command:
"C:\Program Files\atnsoft key remapper\keyremapper.exe" \startup


Scan keyremapper.exe - Powered by Reason Core Security