wtmkm.exe

Macro Key Manager Application

WALTOP International Corporation

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘MacrokeyManager’.
Publisher:
WALTOP International Corporation  (signed and verified)

Product:
Macro Key Manager Application

Description:
Macro Key Manager MFC Application

Version:
1, 0, 0, 1

MD5:
542366c5659be7e4ef3cd86415449b62

SHA-1:
7d92c0c851b4209494a4ee134a88991bceb73d46

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/27/2024 12:25:24 AM UTC  (today)

File size:
1.9 MB (1,969,824 bytes)

Product version:
1, 0, 0, 1

Copyright:
Copyright (C) 2006

Original file name:
Macro Key Manager.EXE

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Windows\System32\wtmkm.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/27/2006 1:00:00 AM

Valid to:
7/18/2007 12:59:59 AM

Subject:
CN=WALTOP International Corporation, OU=software, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=WALTOP International Corporation, L=HsinChu, S=Taiwan, C=TW

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
34FE7770E93C7319019A9D0277AF609E

File PE Metadata
Compilation timestamp:
5/29/2007 1:53:12 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
12288:3cI7r0aSshddzUverADYBu9194qsBTJc0:s8rqsBTJc0

Entry address:
0x141BC

Entry point:
6A, 74, 68, 00, 92, 41, 00, E8, F4, 01, 00, 00, 33, DB, 89, 5D, E0, 53, 8B, 3D, F8, 60, 41, 00, FF, D7, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03, C8, 81, 39, 50, 45, 00, 00, 75, 12, 0F, B7, 41, 18, 3D, 0B, 01, 00, 00, 74, 1F, 3D, 0B, 02, 00, 00, 74, 05, 89, 5D, E4, EB, 27, 83, B9, 84, 00, 00, 00, 0E, 76, F2, 33, C0, 39, 99, F8, 00, 00, 00, EB, 0E, 83, 79, 74, 0E, 76, E2, 33, C0, 39, 99, E8, 00, 00, 00, 0F, 95, C0, 89, 45, E4, 89, 5D, FC, 6A, 02, FF, 15, FC, 65, 41, 00, 59, 83, 0D, 24, C9, 41, 00, FF, 83...
 
[+]

Entropy:
4.5705

Developed / compiled with:
Microsoft Visual C++ v7.1

Code size:
84 KB (86,016 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
MacrokeyManager

Command:
wtmkm.exe


Scan wtmkm.exe - Powered by Reason Core Security