How to remove KMSAuto.exe
            
        
    
    
    
    
    
        
            
                
                    
                    - File Details
 
                    - Overview
 
                    - Analysis
 
                
             
            
                KMSAuto.exe
                
                The module KMSAuto.exe has been detected as Trojan.Agent
                
                
                
                
                File Details
                
                
                    
                        
                            
                            
                        
                        
                        
                            | Product Name: | 
                             | 
                        
                        
                        
                        
                            | Company Name: | 
                             | 
                        
                        
                        
                            | MD5: | 
                            5345af180c40e699c15d685720fb0b1f | 
                        
                        
                        
                        
                            | Size: | 
                            439 KB | 
                        
                        
                        
                            | First Published: | 
                            2017-11-10 00:02:24 (7 years ago) | 
                        
                        
                            | Latest Published: | 
                            2024-05-19 23:00:46 (a year ago) | 
                        
                    
                 
                
                
                    
                        
                            
                            
                        
                        
                            | Status: | 
                            
                            Trojan.Agent (on last analysis) | 
                            
                             | 
                        
                        
                            | Analysis Date: | 
                            2024-05-19 23:00:46 (a year ago) | 
                        
                    
                 
                
                
                
                
                    
                        
                        
                            
                                | %sysdrive%\bkp geral 2017\backup_notejunho2017\meus ocumentos2017\ativado office\2_ativ.2 ofc2013 by adornelas\arquivos | 
                            
                        
                        
                        
                            
                                | %sysdrive%\office 2003 - 2007 - 2010 - 2013 - 2016\application\docs\meu pack\instalador\64 bits\10 - microsoft office 2007 ultimate | 
                            
                        
                        
                        
                            
                                | %sysdrive%\backup_john\documents\outros | 
                            
                        
                        
                        
                            
                                | %sysdrive%\tech-dvd 11\validar windows e office\office 2kx\como administrador\__ativa office 2k3 v1 | 
                            
                        
                        
                        
                            
                                | %sysdrive%\programas\office profissional 2013 32bist ou 64bist\ativado do office 2013 e windows 8.1 | 
                            
                        
                        
                        
                            
                                | %sysdrive%\instalação\instalação windows xp e office\office 2013\office2013_pt-br | 
                            
                        
                        
                        
                            
                                | %desktop%\nova pasta\office 2013 crackk | 
                            
                        
                        
                        
                            
                                | %desktop%\suporte\office 2013\pt_office_professional_plus_2013_x64_vl | 
                            
                        
                        
                        
                            
                                | %desktop%\suporte\office 2013 | 
                            
                        
                        
                        
                            
                                | %sysdrive%\arqinst\office\validar office\ativador office 2013 | 
                            
                        
                        
                    
                 
                
                
                
                
                    
                        
                        
                            | KMSAuto 2.11.exe | 
                        
                        
                        
                            | KMSAuto.exe | 
                        
                        
                        
                            | kmsauto.exe | 
                        
                        
                    
                 
                
                
                
                
                
                
                
                
                
                
                    
                        
                        
                            | Windows 10 | 
                            61.5% | 
                            
                                
                             | 
                        
                        
                        
                            | Windows 7 | 
                            38.5% | 
                            
                                
                             | 
                        
                        
                    
                 
                
                
                
                
                Analysis
                
                
                
                    
                        
                            
                            
                        
                        
                        
                            | Subsystem: | 
                            Windows CUI | 
                        
                        
                            | PE Type: | 
                            pe | 
                        
                        
                            | OS Bitness: | 
                            32 | 
                        
                        
                        
                            | Image Base: | 
                            0x00400000 | 
                        
                        
                            | Entry Address: | 
                            0x000152c8 | 
                        
                    
                 
                
                
                
                
                
                    
                        
                            
                            
                            
                        
                        
                            | Name | 
                            Size of data | 
                            MD5 | 
                        
                        
                        
                            | .text | 
                            81920 | 
                            af6c3004051e07e4d76336daa7b10833 | 
                        
                        
                        
                            | .itext | 
                            3072 | 
                            63234c9bb178c1108eac6d3d39b93620 | 
                        
                        
                        
                            | .data | 
                            3584 | 
                            c874d687e4e51350ee5ec8072c1ff1d2 | 
                        
                        
                        
                            | .bss | 
                            0 | 
                            00000000000000000000000000000000 | 
                        
                        
                        
                            | .idata | 
                            3584 | 
                            e04d7da16f574b365c76ea9e06f0909c | 
                        
                        
                        
                            | .tls | 
                            0 | 
                            00000000000000000000000000000000 | 
                        
                        
                        
                            | .rdata | 
                            512 | 
                            966619ef3923350ca34cbce3977e64eb | 
                        
                        
                        
                            | .reloc | 
                            7168 | 
                            63ec85ee79cdb927f203f6a134e12637 | 
                        
                        
                        
                            | .rsrc | 
                            348672 | 
                            b2417c1bfb531a432ad98e5b16ce6f9a |