How to remove $RBGLYB2.exe
- File Details
- Overview
- Analysis
$RBGLYB2.exe
The module $RBGLYB2.exe has been detected as Hack.KMS
File Details
Product Name: |
|
MD5: |
d2a9369163e5d5f59d23b290615eb669 |
Size: |
1 MB |
First Published: |
2017-09-09 11:13:46 (7 years ago) |
Latest Published: |
2020-01-20 00:09:10 (5 years ago) |
Status: |
Hack.KMS (on last analysis) |
|
Analysis Date: |
2020-01-20 00:09:10 (5 years ago) |
Overview
Signed By: |
WZT |
Status: |
Valid |
%desktop%\kms tools portable 07_06_2016\programs\unicrypt 2016 v2.2 |
%mydoc%\programs to keep\aktivator!!!\kms tools portable 06_08_2016_\programs\unicrypt 2016 v2.2 |
%desktop%\from lyamine\kms tools portable 06.12.2016\programs |
%desktop%\from lyamine\kms tools portable 06.12.2016\kms tools portable 06.12.2016\programs |
%profile%\downloads\kms tools portable 01.11.2016 by ratiborus\programs |
%sysdrive%\admin\ratiborus\programs |
%desktop%\aktivator!!!\kms tools portable 06_08_2016_\programs |
%desktop%\aktivator!!!\kms tools portable 06_08_2016_\programs\pidkey v2.1.2.1015\kms tools portable 06_08_2016_\programs |
%profile%\downloads\kms tools portable 01.11.2016\programs |
%profile%\downloads\compressed\ratiborus.kms.tools.01.11.2016\ratiborus.kms.tools.01.11.2016\programs |
UniCrypt.exe |
$RBGLYB2.exe |
|
13.8% |
|
|
13.8% |
|
|
10.3% |
|
|
10.3% |
|
|
6.9% |
|
|
6.9% |
|
|
6.9% |
|
|
3.4% |
|
|
3.4% |
|
|
3.4% |
|
|
3.4% |
|
|
3.4% |
|
|
3.4% |
|
|
3.4% |
|
|
3.4% |
|
|
3.4% |
|
Windows 10 |
55.2% |
|
Windows 7 |
37.9% |
|
Windows 8.1 |
3.4% |
|
Windows Embedded 8.1 |
3.4% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x00001000 |
Name |
Size of data |
MD5 |
.code |
143872 |
a6347eb9ae6f3a819535d64654524ec4 |
.text |
388608 |
3f85204ea7f1ecf3a766c1f0886ace18 |
.rdata |
48640 |
013bbb5acd6fd134f0334f1d56377148 |
.data |
167936 |
522dd23a273ae1b784a93d0690839c1e |
.rsrc |
713216 |
7ed88dc69a8e9ddc28e51f8f025f6782 |