How to remove AutoKMS.exe
- File Details
- Overview
- Analysis
AutoKMS.exe
The module AutoKMS.exe has been detected as Trojan.Agent
File Details
| Product Name: |
|
| MD5: |
25f0c9aacb93fac01af9dcab14d6840e |
| Size: |
635 KB |
| First Published: |
2017-05-29 06:04:00 (8 years ago) |
| Latest Published: |
2021-02-22 04:53:55 (4 years ago) |
| Status: |
Trojan.Agent (on last analysis) |
|
| Analysis Date: |
2021-02-22 04:53:55 (4 years ago) |
| %windir%\autokms |
| %windir% |
| %sysdrive% |
| %windir% |
| %windir% |
| %windir% |
| %windir% |
| %windir% |
| %windir% |
| %windir% |
|
78.1% |
|
|
3.3% |
|
|
3.0% |
|
|
2.8% |
|
|
2.3% |
|
|
1.8% |
|
|
1.5% |
|
|
1.0% |
|
|
1.0% |
|
|
1.0% |
|
|
1.0% |
|
|
1.0% |
|
|
1.0% |
|
|
1.0% |
|
|
0.3% |
|
| Windows 7 |
80.0% |
|
| Windows 10 |
17.7% |
|
| Windows 8.1 |
1.2% |
|
| Windows Server 2008 R2 |
0.5% |
|
| Windows XP |
0.5% |
|
Analysis
| Subsystem: |
Windows GUI |
| PE Type: |
pe |
| OS Bitness: |
32 |
| Image Base: |
0x00400000 |
| Entry Address: |
0x0004544e |
| MVID: |
7b9e2ca1-dd30-4f57-ab79-4e622e795867 |
| Typelib ID: |
58acc958-754c-480c-9c3b-77a6573ae75e |
| Name |
Size of data |
MD5 |
| .text |
275968 |
9a6fb1612640d00daff0dd910131badf |
| .rsrc |
373760 |
8a61badbda27729b8189dd14216b72c3 |
| .reloc |
512 |
ef313e07341515ba29e70aa32f47933c |