wtmkm.exe

Macro Key Manager Application

WALTOP International Corporation

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘MacrokeyManager’.
Publisher:
WALTOP International Corporation  (signed and verified)

Product:
Macro Key Manager Application

Description:
Macro Key Manager MFC Application

Version:
1, 0, 0, 8

MD5:
1421a93255b19e4bdc6afcff110cb0dd

SHA-1:
f1febf667af51f4692edf1b562aa3ecd0cb9b3dc

SHA-256:
948a1ac50fa35cda0668d747ad9ab4848aa290c40382b2579faac47392ea905a

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 12:35:31 PM UTC  (today)

File size:
5.3 MB (5,586,664 bytes)

Product version:
1, 0, 0, 1

Copyright:
Copyright (C) 2006

Original file name:
Macro Key Manager.EXE

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Windows\System32\wtmkm.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/19/2009 2:00:00 AM

Valid to:
7/17/2010 1:59:59 AM

Subject:
CN=WALTOP International Corporation, OU=software, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=WALTOP International Corporation, L=HsinChu, S=Taiwan, C=TW

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0BC4E5340CF9CD16938F237A5382B62A

File PE Metadata
Compilation timestamp:
9/10/2009 3:44:54 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
12288:/osURiHqjBBBJ2Ot6+M/n8HSkIG4Nw2Vp7QBEk9ki9m02DOQ5Kd8edEeEKWW9xp6:MjjBBBJ2OA+HSc2D7ukdB2YjFn

Entry address:
0x156DC

Entry point:
6A, 74, 68, 08, B3, 41, 00, E8, F4, 01, 00, 00, 33, DB, 89, 5D, E0, 53, 8B, 3D, F8, 80, 41, 00, FF, D7, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03, C8, 81, 39, 50, 45, 00, 00, 75, 12, 0F, B7, 41, 18, 3D, 0B, 01, 00, 00, 74, 1F, 3D, 0B, 02, 00, 00, 74, 05, 89, 5D, E4, EB, 27, 83, B9, 84, 00, 00, 00, 0E, 76, F2, 33, C0, 39, 99, F8, 00, 00, 00, EB, 0E, 83, 79, 74, 0E, 76, E2, 33, C0, 39, 99, E8, 00, 00, 00, 0F, 95, C0, 89, 45, E4, 89, 5D, FC, 6A, 02, FF, 15, 38, 86, 41, 00, 59, 83, 0D, 94, F9, 41, 00, FF, 83...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v7.1

Code size:
92 KB (94,208 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
MacrokeyManager

Command:
wtmkm.exe


Scan wtmkm.exe - Powered by Reason Core Security