How to remove KMSpico.exe
- File Details
- Overview
- Analysis
KMSpico.exe
The module KMSpico.exe has been detected as Hack.AutoKMS
File Details
| Product Name: |
|
| Company Name: |
|
| MD5: |
d870afd18985c91aa83e1236642aea4d |
| Size: |
1 MB |
| First Published: |
2017-09-03 18:04:17 (8 years ago) |
| Latest Published: |
2021-01-03 09:58:08 (4 years ago) |
| Status: |
Hack.AutoKMS (on last analysis) |
|
| Analysis Date: |
2021-01-03 09:58:08 (4 years ago) |
| %desktop%\cursos\programas ms-project 2010\crack - ms project\kmspico oem\$oem$\$$\setup\scripts |
| %sysdrive%\ale\ale\software\ms office 2013\activator office 2013\kmspico activator 5.1\kmspico oem\$oem$\$$\setup |
| %sysdrive%\upda\office\kmspico v5.1\kmspico oem\$oem$\$$\setup |
| %sysdrive%\desktop 2 oct\ms office 2013\kmspico_v5.1_woc.rar\kmspico_v5.1_woc\kmspico oem\$oem$\$$\setup |
| %sysdrive%\desktop 2 oct\ms office 2013\kmspico_v5.1_woc\kmspico oem\$oem$\$$\setup |
| %sysdrive%\$recycle.bin\s-1-5-21-87135576-2087611795-607172523-1000\$rfx3m3o\activador win8 y office 2013 31-may-2013.rar\activador win8 y office 2013 31-may-2013\kmspico oem\$oem$\$$\setup |
| %sysdrive%\$recycle.bin\s-1-5-21-87135576-2087611795-607172523-1000\$rfx3m3o\activador win8 y office 2013 31-may-2013\kmspico oem\$oem$\$$\setup |
| %sysdrive%\$recycle.bin\s-1-5-21-87135576-2087611795-607172523-1000\$rfx3m3o\activador win8 y office 2013 31-may-2013\kms spico[expert2program.blogspot.com].rar\kmspico oem\$oem$\$$\setup |
| %desktop%\kmspico_5.1\kmspico oem\$oem$\$$\setup |
| %profile%\downloads\office13proplus\kmspico_5.1\kmspico_5.1\kmspico oem\$oem$\$$\setup |
|
18.8% |
|
|
14.6% |
|
|
10.4% |
|
|
6.3% |
|
|
6.3% |
|
|
6.3% |
|
|
4.2% |
|
|
4.2% |
|
|
4.2% |
|
|
4.2% |
|
|
2.1% |
|
|
2.1% |
|
|
2.1% |
|
|
2.1% |
|
|
2.1% |
|
|
2.1% |
|
|
2.1% |
|
|
2.1% |
|
|
2.1% |
|
|
2.1% |
|
| Windows 10 |
68.8% |
|
| Windows 7 |
27.1% |
|
| Windows 8.1 |
4.2% |
|
Analysis
| Subsystem: |
Windows GUI |
| PE Type: |
pe |
| OS Bitness: |
32 |
| Image Base: |
0x00400000 |
| Entry Address: |
0x000168cf |
| Name |
Size of data |
MD5 |
| .text |
90624 |
4794b31aa8ab9b337e775f7340a2271d |
| .rdata |
14336 |
4db2dba763a9460e4543f48d7929b457 |
| .data |
2048 |
948353a21f43eb6ad7b646bc00bb4688 |
| .rsrc |
372224 |
96640076b64aa94fe35c30a0dd7032ec |