How to remove officekms.exe
- File Details
- Overview
- Analysis
officekms.exe
The module officekms.exe has been detected as Trojan.Agent
File Details
Product Name: |
|
Company Name: |
|
MD5: |
39e5b7e7a52c4f6f86f086298950c6b8 |
Size: |
2 MB |
First Published: |
2020-02-13 14:27:28 (4 years ago) |
Latest Published: |
2020-04-08 05:12:24 (4 years ago) |
Status: |
Trojan.Agent (on last analysis) |
|
Analysis Date: |
2020-04-08 05:12:24 (4 years ago) |
%commonappdata% |
%commonappdata% |
%commonappdata% |
%commonappdata% |
%commonappdata% |
%commonappdata% |
%commonappdata% |
%commonappdata% |
%commonappdata% |
%sysdrive%\$recycle.bin |
|
63.5% |
|
|
31.8% |
|
|
2.4% |
|
|
1.2% |
|
|
1.2% |
|
Windows 10 |
83.5% |
|
Windows 7 |
14.1% |
|
Windows Server 2016 |
1.2% |
|
Windows 8.1 |
1.2% |
|
Analysis
Subsystem: |
Windows CUI |
PE Type: |
pe |
OS Bitness: |
64 |
Image Base: |
0x0000000140000000 |
Entry Address: |
0x0015c68c |
Name |
Size of data |
MD5 |
.text |
1759232 |
730cbc23feaae11290cddea6a55804e7 |
.rdata |
306176 |
2ef05bf8aaedc9416f96df08ba623ee1 |
.data |
257536 |
4f4b92f3ff15254dc113073023c61baf |
.pdata |
57856 |
44607192754381095888decf144f4046 |
_RANDOMX |
2048 |
4c9ad32e381e3b0d5fe17bbaafaae2bf |
_TEXT_CN |
6656 |
6a7f77e47f77f65bef85036ae5a71106 |
_TEXT_CN |
4608 |
409bf3f918f2402291cb56c2e9354b47 |
_RDATA |
512 |
287ad841f8f4b2a05333d306638c47dc |
.rsrc |
23040 |
13aab1be412f17c9c13ab9d7ab77ae7e |
.reloc |
9728 |
4c21710f419583215afdf597209b7ca7 |