Information about actkey64.exe

actkey64.exe

actkey64.exe is a Windows file recorded in the ThreatInfo database. It is associated with Remo Recover Windows. The reported company name is Remo Software. The current detection status is Undefined, based on the latest analysis from 2021-01-01 10:54:36 (5 years ago).

ThreatInfo does not have a final classification for this file yet. Use the technical details below to compare the hash, size, signature, and observed locations with the copy found on your device.

Product Name: Remo Recover Windows
Company Name: Remo Software
MD5: 77c2dacf547006ffabfbd19bd3b95c05
Size: 1 MB
First Published: 2021-01-01 10:54:36 (5 years ago)
Latest Published: 2021-01-01 10:54:36 (5 years ago)
Status: Undefined (on last analysis)
Analysis Date: 2021-01-01 10:54:36 (5 years ago)
Signed By: Remo Software
Status: Valid

The signature on actkey64.exe is reported as valid. A valid signature helps confirm publisher identity, but it does not automatically make the file safe if the installer was bundled, abused, or downloaded from an untrusted source.

%programfiles%\remo recover 5.0

ThreatInfo has observed actkey64.exe in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

100.0%

The strongest geographic signal for this file is Iran, Islamic Republic of with 100.0% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 100.0%

The most common operating system signal for actkey64.exe is Windows 10 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

actkey64.exe is identified as pe for 64 systems. The subsystem is Windows GUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Windows GUI
PE Type: pe
OS Bitness: 64
Image Base: 0x0000000140000000
Entry Address: 0x0010a560

PE Sections:

Name Size of data MD5
.text 0 00000000000000000000000000000000
.rdata 0 00000000000000000000000000000000
.data 0 00000000000000000000000000000000
.pdata 0 00000000000000000000000000000000
.idata 0 00000000000000000000000000000000
.reloc 0 00000000000000000000000000000000
.text1 561152 53cff51c27fd364d6ddb2ba273fceb60
.adata 4096 e2ae1302b399b533c2965fce9f0ab03b
.data1 258048 2f0ef6e88288ab734a277c37a109eeb9
.pdata1 49152 8600f889007ae67348d95c1b70c585eb
.rsrc 4096 620f0b67a91f7f74151bc5be745b7110
.reloc1 8192 7cad3942ec2e1e80e9f340d70bed0ebf
.pdata2 647168 23dc74b28bbcd5729873ab471050383b
.rsrc1 258048 4e94124e5866c408000de7c2fab5dd43

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information: