How to remove AutoKMS.exe
- File Details
- Overview
- Analysis
AutoKMS.exe
The module AutoKMS.exe has been detected as Trojan.Agent
File Details
MD5: |
d4f602b1f775b5827932d3c5b04a3fd2 |
Size: |
3 MB |
First Published: |
2017-05-22 03:01:04 (6 years ago) |
Latest Published: |
2022-05-26 23:23:11 (2 years ago) |
Status: |
Trojan.Agent (on last analysis) |
|
Analysis Date: |
2022-05-26 23:23:11 (2 years ago) |
%windir%\autokms |
%sysdrive%\system volume information\systemrestore\frstaging\windows\autokms |
%appdata%\zhp\quarantine |
%appdata%\zhp\quarantine\autokms |
%windir% |
%appdata%\zhp |
%windir% |
%windir% |
%windir% |
%windir% |
|
39.3% |
|
|
10.1% |
|
|
7.1% |
|
|
4.9% |
|
|
3.8% |
|
|
3.5% |
|
|
2.0% |
|
|
2.0% |
|
|
1.8% |
|
|
1.6% |
|
|
1.6% |
|
|
1.5% |
|
|
1.5% |
|
|
1.5% |
|
|
1.3% |
|
|
1.1% |
|
|
0.9% |
|
|
0.9% |
|
|
0.9% |
|
|
0.7% |
|
|
0.7% |
|
|
0.7% |
|
|
0.7% |
|
|
0.7% |
|
|
0.7% |
|
|
0.7% |
|
|
0.5% |
|
|
0.5% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
Windows 7 |
69.6% |
|
Windows 10 |
19.1% |
|
Windows 8.1 |
7.3% |
|
Windows 8 |
2.4% |
|
Windows Server 2008 R2 |
0.5% |
|
Windows XP |
0.5% |
|
Windows Server 2003 |
0.2% |
|
Windows Embedded Standard |
0.2% |
|
Windows Server 2012 R2 |
0.2% |
|
Analysis
Subsystem: |
Windows CUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x002dd84e |
MVID: |
2a867ca4-949b-48f1-9425-c79a54a4e088 |
Typelib ID: |
3e577747-1842-4364-af1e-ed2a30c03f61 |
Name |
Size of data |
MD5 |
.text |
2996736 |
6115db07d91f4ac4ab012bd4c94cb77b |
.rsrc |
374272 |
ca7cb72402f5ad45504edd1fa857d5e0 |
.reloc |
512 |
f09ddfbddbeb7e06c7736347f4525223 |