Kmaestro64.exe

Kmaestro (x64)

Behavior Tech Computer Corp.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘BtcMaestro’.
Publisher:
Kmaestro  (signed by Behavior Tech Computer Corp.)

Product:
Kmaestro (x64)

Description:
KeyMaestro (x64) main program

Version:
1, 0, 0, 0

MD5:
6b708a4cf5e1b65a7d6100e8b9b21392

SHA-1:
10df4ee2cabe4efd6aff6e1abf23ca56f5ef8eb1

SHA-256:
dd284025586bd102bff532f1b3b81bd31bad41ab9fef36dbbcd61ff0d066230c

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/18/2024 1:48:31 PM UTC  (today)

File size:
366.8 KB (375,632 bytes)

Product version:
1, 0, 0, 0

Copyright:
Copyright c 2006

Original file name:
Kmaestro64.exe

File type:
Executable application (Win64 EXE)

Common path:
C:\Program Files\kmaestro\kmaestro64.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/20/2006 4:00:00 AM

Valid to:
7/17/2009 3:59:59 AM

Subject:
CN=Behavior Tech Computer Corp., OU=R & D Engineering Optical Storage Division, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Behavior Tech Computer Corp., L=Taipei, S=Taiwan, C=TW

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1023504091ABF80F6EB3441B2376A176

File PE Metadata
Compilation timestamp:
11/3/2006 5:19:27 AM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:we9qr5DXm7O+9CPYUh9YdOcsYiaQXr/mO:we9W5TmZCPYSJcKr/

Entry address:
0x200A0

Entry point:
48, 83, EC, 28, E8, D7, 3B, 00, 00, 48, 83, C4, 28, E9, FE, FC, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 48, 81, EC, 88, 00, 00, 00, 48, 85, C9, 4C, 89, 64, 24, 60, 4C, 89, 6C, 24, 58, 4C, 89, 74, 24, 50, 45, 8B, E1, 4D, 8B, E8, 4C, 8B, F2, C6, 44, 24, 48, 00, 0F, 85, 97, 00, 00, 00, E8, 8E, 16, 00, 00, 48, 89, 44, 24, 40, 4C, 8B, 90, C0, 00, 00, 00, 4C, 3B, 15, 8B, FE, 00, 00, 4C, 89, 54, 24, 30, 4C, 8B, 98, B8, 00, 00, 00, 4C, 89, 5C, 24, 38, 74, 25, 8B, 88, C8, 00, 00, 00, 85, 0D...
 
[+]

Code size:
148 KB (151,552 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
BtcMaestro

Command:
"C:\Program Files\kmaestro\kmaestro64.exe"


Scan Kmaestro64.exe - Powered by Reason Core Security