How to remove KMSAuto Net.exe
- File Details
- Overview
- Analysis
KMSAuto Net.exe
The module KMSAuto Net.exe has been detected as Hack.KMS
File Details
Product Name: |
|
Company Name: |
|
MD5: |
50bdfff7f8553ec23242344c02d69c61 |
Size: |
1 MB |
First Published: |
2017-07-30 14:05:36 (7 years ago) |
Latest Published: |
2021-02-09 16:46:54 (4 years ago) |
Status: |
Hack.KMS (on last analysis) |
|
Analysis Date: |
2021-02-09 16:46:54 (4 years ago) |
%sysdrive%\activator |
%sysdrive%\activation |
%sysdrive%\$recycle.bin\s-1-5-21-4274195575-364792600-1176264712-1001 |
%sysdrive%\документы\koc\activation |
%sysdrive%\$recycle.bin\s-1-5-21-2820970667-1797332266-2132351356-1001\$rt1eo4s\koc\activation |
%sysdrive% |
%commonappdata% |
%sysdrive%\$recycle.bin\s-1-5-21-320895605-1000683678-3392730922-1001 |
%sysdrive%\down\mso_13\off2013_pro\activation\activation.zip |
%desktop%\ms office 2013\activation\activation.zip |
|
65.0% |
|
|
20.0% |
|
|
5.0% |
|
|
5.0% |
|
|
5.0% |
|
Windows 10 |
70.0% |
|
Windows 7 |
20.0% |
|
Windows 8.1 |
10.0% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x001cba3e |
MVID: |
d1e4c5ad-d09c-4cc3-997c-eddf1c48f783 |
Typelib ID: |
fcad9796-cfc1-41fa-93da-378996c2a356 |
Name |
Size of data |
MD5 |
.text |
1874944 |
83e3d25d4cc877dcecdad2a2c3d513bd |
.rsrc |
48640 |
cd5723324eaa84a2f5a9e8826e76cb5f |
.reloc |
512 |
3416f367784b51392d172b105508eff9 |