How to remove AutoKMS.exe
- File Details
- Overview
- Analysis
AutoKMS.exe
The module AutoKMS.exe has been detected as Trojan.Agent
File Details
MD5: |
6852a0ac61131f03b516e627fac86d1a |
Size: |
5 MB |
First Published: |
2017-05-21 07:08:23 (6 years ago) |
Latest Published: |
2023-09-28 23:17:57 (7 months ago) |
Status: |
Trojan.Agent (on last analysis) |
|
Analysis Date: |
2023-09-28 23:17:57 (7 months ago) |
%windir%\autokms |
%programfiles%\panda security\panda security protection\lostandfound |
%sysdrive%\windows.old\windows\autokms |
%appdata%\zhp\quarantine |
%windir% |
%programfiles%\panda security\panda security protection |
%sysdrive%\uyuhbu29g7oxa5wh\uyuhbu29g7oxa5wh |
%appdata%\zhp |
%sysdrive%\$recycle.bin |
%windir% |
AutoKMS.exe |
{0F901FA8-0196-40FA-AA51-5CC0588A0688} |
$RLDKZ6Y.exe |
autokms.exe |
|
12.1% |
|
|
8.5% |
|
|
6.2% |
|
|
5.4% |
|
|
4.6% |
|
|
4.3% |
|
|
4.0% |
|
|
3.6% |
|
|
3.6% |
|
|
3.3% |
|
|
2.5% |
|
|
2.4% |
|
|
2.3% |
|
|
2.3% |
|
|
2.0% |
|
|
1.6% |
|
|
1.4% |
|
|
1.3% |
|
|
1.2% |
|
|
1.1% |
|
|
1.1% |
|
|
1.1% |
|
|
1.1% |
|
|
1.0% |
|
|
0.9% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.7% |
|
|
0.7% |
|
|
0.7% |
|
|
0.7% |
|
|
0.7% |
|
|
0.6% |
|
|
0.6% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
Windows 10 |
61.0% |
|
Windows 7 |
29.0% |
|
Windows 8.1 |
7.6% |
|
Windows 8 |
0.8% |
|
Windows Server 2012 R2 |
0.8% |
|
Windows Vista |
0.3% |
|
Windows Server 2016 |
0.2% |
|
Windows Embedded 8.1 |
0.1% |
|
Windows Server 2008 R2 |
0.1% |
|
Windows XP |
0.1% |
|
Analysis
Subsystem: |
Windows CUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x0058dcca |
MVID: |
c4636b07-01f5-4549-90c4-f1b2a0fcd9b2 |
Name |
Size of data |
MD5 |
.text |
5815808 |
73881c7dd67c9bda1b37d5136bc94d02 |
.rsrc |
374784 |
af2a6db461be0a0d4dda411f5bfdb155 |
.reloc |
512 |
e6da84371099234404053f6f960bdba4 |