How to remove KMSAuto Net.exe
- File Details
- Overview
- Analysis
KMSAuto Net.exe
The module KMSAuto Net.exe has been detected as General Threat
File Details
Product Name: |
|
Company Name: |
|
MD5: |
4ee421972c0adc20debb48d01f9daf17 |
Size: |
6 MB |
First Published: |
2017-07-06 14:12:52 (7 years ago) |
Latest Published: |
2018-11-16 19:08:03 (6 years ago) |
Status: |
General Threat (on last analysis) |
|
Analysis Date: |
2018-11-16 19:08:03 (6 years ago) |
%commonappdata%\kmsautos |
%commonappdata% |
%sysdrive%\重要資料\win7\documents\files |
%sysdrive%\重要資料\win7\documents\files\office2013 |
%sysdrive%\lin-pc\backup set 2016-12-26 132047\backup files 2016-12-26 132047\backup files 12.zip\c\users\lin\desktop |
%sysdrive%\lin-pc\backup set 2016-05-29 190000\backup files 2016-05-29 190000\backup files 12.zip\c\users\lin\desktop |
%sysdrive%\lin-pc\backup set 2018-05-22 100546\backup files 2018-05-22 100546\backup files 12.zip\c\users\lin\desktop |
%desktop%\linx\新增資料夾 |
%sysdrive%\lin-pc\backup set 2016-10-16 190001\backup files 2016-10-16 190001\backup files 12.zip\c\users\lin\desktop |
%sysdrive%\lin-pc\backup set 2016-03-19 222259\backup files 2016-03-19 222259\backup files 12.zip\c\users\lin\desktop |
Windows 7 |
81.3% |
|
Windows 10 |
18.8% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x006b900a |
MVID: |
57adaf3f-f9cc-4f31-9dd0-0004cb92c0c1 |
Typelib ID: |
fcaa9736-cfc3-43fa-33da-378396c3a336 |
Name |
Size of data |
MD5 |
.text |
7041536 |
63acd06f64f70a4d291bbaa01f8132f1 |
.rsrc |
48640 |
8f7db7ec9a9212bd188f851600f21321 |
.reloc |
512 |
94e8a0c4ebc6b8e215dc04613158267b |