How to remove KMSAuto.Lite_1.3.1-[www.Patoghu.com].exe
- File Details
- Overview
- Analysis
KMSAuto.Lite_1.3.1-[www.Patoghu.com].exe
The module KMSAuto.Lite_1.3.1-[www.Patoghu.com].exe has been detected as Hack.AutoKMS
File Details
MD5: |
6bf0a53e1823b2cedd3e0f30a277dec1 |
Size: |
6 MB |
First Published: |
2017-05-22 08:09:33 (7 years ago) |
Latest Published: |
2024-09-30 23:07:14 (4 months ago) |
Status: |
Hack.AutoKMS (on last analysis) |
|
Analysis Date: |
2024-09-30 23:07:14 (4 months ago) |
Overview
Signed By: |
WZTeam |
Status: |
Valid |
%sysdrive%\windows |
%sysdrive%\activators\kmsautolite |
%desktop%\programlar |
%profile%\downloads\compressed\kmsauto.lite_1.3.1-[www.patoghu.com] |
%temp%\wiserar1883bfb8$.tmp\kmsal131mp [bagas31]1 |
%localappdata%\temp |
%sysdrive%\$recycle.bin\s-1-5-21-2870122749-1004376450-2501486741-1002\$rczv6et\autoplay\docs |
%temp%\rar$exa0.542\kmsauto lite v1.3.1 (portable) |
%temp%\rar$exa0.540\kmsauto lite v1.3.1 (portable) |
%appdata%\cyberlink\power2go\7.0\temp\programs\kmsauto lite portable v1.3.1 |
KMSAuto.exe |
KMSAuto.Lite_1.3.1-[www.Patoghu.com].exe |
KMS.exe |
KMSAuto (2017_08_10 13_53_02 UTC).exe |
KMSAuto (2017_09_08 22_28_09 UTC).exe |
$R4OFM2F.exe |
KMSAuto_IObitDel.exe |
avz00003.dta |
$RWJOWVD.quarantined |
kmsauto.exe |
|
44.6% |
|
|
26.0% |
|
|
2.7% |
|
|
2.4% |
|
|
1.7% |
|
|
1.6% |
|
|
1.5% |
|
|
1.3% |
|
|
1.1% |
|
|
0.9% |
|
|
0.9% |
|
|
0.9% |
|
|
0.8% |
|
|
0.7% |
|
|
0.7% |
|
|
0.6% |
|
|
0.6% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.4% |
|
|
0.4% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
Windows 10 |
68.8% |
|
Windows 7 |
24.1% |
|
Windows 8.1 |
5.8% |
|
Windows 8 |
0.5% |
|
Windows XP |
0.3% |
|
Windows Server 2008 R2 |
0.2% |
|
Windows Vista |
0.1% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x00001000 |
Name |
Size of data |
MD5 |
.code |
114688 |
8463dec0275e25e0696bae77f2d8d5dc |
.text |
360448 |
d66459eb189995485c155feafa157359 |
.rdata |
37888 |
e6187ad982d9d7967a02a7f08bebbfe5 |
.data |
5984768 |
1af256fee963bd7282d1c11997bdd1d0 |
.rsrc |
45568 |
d6cfe208b3f21e42d13ef7bed64ba234 |