How to remove Service_KMS.exe
- File Details
- Overview
- Analysis
Service_KMS.exe
The module Service_KMS.exe has been detected as Trojan.AutoKMS
File Details
Product Name: |
|
MD5: |
c677b0f16e5e04cdc7621dc8c8d9b839 |
Size: |
484 KB |
First Published: |
2017-07-11 08:06:40 (7 years ago) |
Latest Published: |
2020-07-27 17:31:33 (4 years ago) |
Status: |
Trojan.AutoKMS (on last analysis) |
|
Analysis Date: |
2020-07-27 17:31:33 (4 years ago) |
%programfiles%\kmspico |
%programfiles% |
%sysdrive%\dysk_h\###-software\release.v8.0.final.cheva.softarchive.net.7z\kmspico.v8.final |
%sysdrive%\kedai photo file\penting\buat laptop baru\kmspico8.rar\kmspico 8 final |
%sysdrive%\imprescindibles\win_7\kmspico v8.0 final - activar windows y office.rar\kmspico v8.0 final |
%sysdrive%\aplikasi @amp; software\windows @amp; office\kmspico8.rar\kmspico 8 final |
%programfiles% |
%programfiles% |
%windir%\kms pico windows 8.1 release.v8.0 by softwaresactivate.blogspot.com\windows 8.1 release.v8.0\kmspico.v8.final |
%windir%\windows 8.1 release.v8.0 by softwaresactivate.blogspot.com.zip\windows 8.1 release.v8.0\kmspico.v8.final |
|
46.2% |
|
|
30.8% |
|
|
7.7% |
|
|
7.7% |
|
|
7.7% |
|
Windows 7 |
46.2% |
|
Windows 10 |
38.5% |
|
Windows 8 |
15.4% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x0007953e |
MVID: |
3e0c3ed2-9103-47c2-a66c-b8bac92bc4cd |
Typelib ID: |
9a79266f-9bd7-4979-82c2-2f910d03f9bf |
Name |
Size of data |
MD5 |
.text |
488960 |
07122b66902c366c41459edbe95208c2 |
.sdata |
512 |
a725019b2ad693fafb4286f688f6fe3b |
.rsrc |
5120 |
089b5a7a456f6a8b15eb7813c3b6937a |
.reloc |
512 |
08cb4bbd7ace464c1f004206108a8446 |