PCKeeper.exe

PCKeeper

KROMTECH ALLIANCE CORP

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘PCKeeper2’.
Publisher:
Kromtech  (signed by KROMTECH ALLIANCE CORP)

Product:
PCKeeper

Description:
PCKeeper native shim

Version:
2.2.244.14599

MD5:
54b9194f1a7e55b0cae1c91a2ae557eb

SHA-1:
52dc7805be9a9b8992c48d604cf27d3f2e05b7a2

SHA-256:
aa5702674d1c86d416c2d19a6f818193228ded7e3e02cb649fbaab90afe43a9b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 1:13:08 PM UTC  (today)

File size:
457 KB (467,984 bytes)

Product version:
2.2.244.14599

Copyright:
(c) Kromtech Alliance Corp. All rights reserved.

Original file name:
PCKeeper.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\kromtech\pckeeper live\pckeeper.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/11/2013 5:30:00 AM

Valid to:
6/12/2014 5:29:59 AM

Subject:
CN=KROMTECH ALLIANCE CORP, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=KROMTECH ALLIANCE CORP, L=Road Town, S=Tortola, C=VG

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1CA24DC01432D2A35756E3093E0AD9FC

File PE Metadata
Compilation timestamp:
3/7/2014 2:49:36 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x6E20

Entry point:
48, 83, EC, 28, E8, 53, 55, 00, 00, 48, 83, C4, 28, E9, 52, FE, FF, FF, CC, CC, 40, 53, 48, 83, EC, 20, BA, 08, 00, 00, 00, 8D, 4A, 18, E8, 51, 22, 00, 00, 48, 8B, C8, 48, 8B, D8, FF, 15, F5, B4, 00, 00, 48, 89, 05, 16, 5C, 01, 00, 48, 89, 05, 07, 5C, 01, 00, 48, 85, DB, 75, 05, 8D, 43, 18, EB, 06, 48, 83, 23, 00, 33, C0, 48, 83, C4, 20, 5B, C3, CC, 48, 89, 5C, 24, 08, 48, 89, 74, 24, 10, 48, 89, 7C, 24, 18, 41, 54, 41, 55, 41, 56, 48, 83, EC, 20, 4C, 8B, F1, E8, 13, 1E, 00, 00, 90, 48, 8B, 0D, CF, 5B, 01...
 
[+]

Entropy:
6.7247

Code size:
67 KB (68,608 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
PCKeeper2

Command:
"C:\Program Files\kromtech\pckeeper live\pckeeper.exe" \autorun


Scan PCKeeper.exe - Powered by Reason Core Security