How to remove KMSAuto Net.exe
- File Details
- Overview
- Analysis
KMSAuto Net.exe
The module KMSAuto Net.exe has been detected as Trojan.Agent
File Details
Product Name: |
|
Company Name: |
|
MD5: |
2f37d022db8632b90567df81fc6931d8 |
Size: |
8 MB |
First Published: |
2017-06-24 16:03:21 (7 years ago) |
Latest Published: |
2020-12-05 14:38:34 (4 years ago) |
Status: |
Trojan.Agent (on last analysis) |
|
Analysis Date: |
2020-12-05 14:38:34 (4 years ago) |
%commonappdata%\kmsautos |
%sysdrive%\$recycle.bin\s-1-5-21-60623584-1570728305-94897453-1000\$r0isj66\backup set 2017-06-09 150438\backup files 2017-06-09 150438\backup files 2.zip\c\users\lyj win7 |
%sysdrive%\$recycle.bin\s-1-5-21-60623584-1570728305-94897453-1000\$r0isj66\backup set 2017-06-09 150438\backup files 2017-06-09 150438\backup files 2.zip\c\users\lyj win7 |
Windows 7 |
83.3% |
|
Windows 10 |
16.7% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x0083e1b2 |
MVID: |
0c061b22-b435-459c-b01e-89760f3e7247 |
Typelib ID: |
fcaa9736-cfc3-43fa-33da-378396c3a336 |
Name |
Size of data |
MD5 |
.text |
8635392 |
31bbd7f6b93b08920fe0d62d386dd8e4 |
.rsrc |
49152 |
0544a4d4abf195e3616b17903b465ad2 |
.reloc |
512 |
4f8babd4da85c306c1c51e7cb978f45a |