How to remove AutoKMS.exe

AutoKMS.exe

The module AutoKMS.exe has been detected as Trojan.Agent

AutoKMS.exe
MD5: dd3a4bebe7ea3e75f71f3d9e9e2aa016
Size: 3 MB
First Published: 2017-05-21 06:06:09 (6 years ago)
Latest Published: 2024-04-01 23:07:07 (2 weeks ago)
Status: Trojan.Agent (on last analysis)
Analysis Date: 2024-04-01 23:07:07 (2 weeks ago)
%windir%\autokms
%appdata%\zhp\quarantine
%programfiles%\panda security\panda security protection\lostandfound
%windir%
%sysdrive%\5d94wsdxy8xel2hr\g2mihitafihswp3c
%profile%\downloads
%windir%
%windir%
%windir%
%windir%
23.5%
8.2%
7.0%
6.2%
4.4%
4.2%
3.3%
3.3%
3.0%
2.1%
2.1%
1.8%
1.8%
1.4%
1.4%
1.2%
1.2%
1.2%
1.2%
1.1%
1.1%
1.1%
1.0%
0.8%
0.8%
0.8%
0.8%
0.8%
0.7%
0.7%
0.7%
0.5%
0.5%
0.5%
0.5%
0.5%
0.4%
0.4%
0.4%
0.4%
0.4%
0.4%
0.4%
0.4%
0.4%
0.4%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
Windows 7 43.7%
Windows 8.1 29.4%
Windows 10 23.0%
Windows 8 2.2%
Windows Server 2008 R2 0.7%
Windows Server 2012 R2 0.4%
Windows Embedded 8.1 0.4%
Windows XP 0.3%
Subsystem: Windows CUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x00345bf4

.NET Info:

MVID: 8be6a452-a338-4bb6-b8aa-35cb0d6ab0c8
Typelib ID: 3e577747-1842-4364-af1e-ed2a30c03f61

PE Sections:

Name Size of data MD5
.text 3423232 996d9c17bd5d35d50e60544fcc667ee5
.rsrc 374272 4c9cbe07981d19c4c52717c7f1501885
.reloc 512 10de49129a612086e0cee59682b5f963

More information:

Download GridinSoft Anti-Malware - Removal tool for AutoKMS.exe