How to remove $RMYNGF4.exe

$RMYNGF4.exe

The module $RMYNGF4.exe has been detected as PUP.HackKMS

$RMYNGF4.exe
Product Name:

KMSAuto Lite

Company Name:

Ratiborus, MSFree Inc.

MD5: 4fb4caecab9b7c3fae2affae8dd38409
Size: 5 MB
First Published: 2017-05-21 07:08:24 (8 years ago)
Latest Published: 2022-08-02 23:23:31 (3 years ago)
Status: PUP.HackKMS (on last analysis)
Analysis Date: 2022-08-02 23:23:31 (3 years ago)
%sysdrive%\windows
%profile%\downloads\compressed\kmsauto lite portable test4
%desktop%\microsoft office 2016 professional plus 16.0.6366.2025 + crack\crack\kmsauto 2.8
%profile%\downloads\compressed\microsoft office professional plus 2016 final vl 64bit\microsoft office professional plus 2016 final vl 64bit\kmsauto lite portable-husaintricks.com
%profile%\downloads\microsoft office 2016 professional plus + ativador - www.dtorrent.com.br\ativador
%programfiles%\microsoft office\root\crack
%programfiles%\microsoft office\office16
%profile%\downloads\microsoft office 2016 professional plus 16.0.6366.2025 + crack\crack\kmsauto 2.8
%programfiles%\microsoft office
%sysdrive%\$recycle.bin\s-1-5-21-3504510149-547488387-2033739256-1001
KMSAuto.exe
$RMYNGF4.exe
KMSAutoLite.exe
office 2016 orjinal yapma.exe
$R3UTQ53.exe
TmpF712.tmp
TmpCC06.tmp
KMSAut222o.exe
KMSAutoNet.exe
e8e3ba21-7ffd-4c01-a7c6-cfa187ca9161.tmp
$R1NFQZT.exe
KMSAuto
Taiwan 28.1%
Brazil 14.0%
Russia 7.3%
Hong Kong 6.5%
Ethiopia 4.8%
Vietnam 3.8%
Ukraine 3.4%
Indonesia 2.6%
Turkey 2.6%
Italy 2.5%
Thailand 1.9%
Czech Republic 1.9%
Nigeria 1.4%
United States 1.4%
Israel 1.2%
India 1.2%
Japan 1.0%
Switzerland 0.9%
Myanmar 0.8%
Egypt 0.7%
Laos 0.7%
Pakistan 0.7%
Austria 0.6%
Canada 0.6%
Slovakia 0.5%
Cambodia 0.5%
Portugal 0.5%
Romania 0.5%
Germany 0.4%
Malaysia 0.4%
Philippines 0.4%
New Zealand 0.3%
Azerbaijan 0.3%
Kazakhstan 0.3%
Bosnia and Herzegovina 0.3%
Morocco 0.3%
Belarus 0.3%
Bangladesh 0.3%
Australia 0.2%
Macau 0.2%
Estonia 0.2%
Kenya 0.2%
Netherlands 0.2%
Denmark 0.2%
Sweden 0.2%
South Korea 0.2%
France 0.2%
Bhutan 0.1%
Bahrain 0.1%
United Kingdom 0.1%
Yemen 0.1%
Greece 0.1%
Angola 0.1%
Saudi Arabia 0.1%
Palestine 0.1%
Uzbekistan 0.1%
Lithuania 0.1%
Kyrgyzstan 0.1%
Iran 0.1%
Panama 0.1%
United Arab Emirates 0.1%
Gabon 0.1%
South Africa 0.1%
Costa Rica 0.1%
Argentina 0.1%
Hungary 0.1%
Singapore 0.1%
Windows 10 69.1%
Windows 7 23.2%
Windows 8.1 6.7%
Windows Server 2008 R2 0.4%
Windows 8 0.3%
Windows Vista 0.2%
Windows Server 2012 R2 0.1%
Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x00001000

PE Sections:

Name Size of data MD5
.code 103936 9d32d983c6ed84bbb0d56a9a9da80b30
.text 307200 536c2dec49ba6c8f9dac97d3ba50b6eb
.rdata 35840 72679c95f19163a0118d222b12234a57
.data 5672448 0bf905855e532632d4c65ec49fe6fc75
.rsrc 45568 f27017dac37e311dfd5f26f93a671eda

More information:

Download GridinSoft Anti-Malware - Removal tool for $RMYNGF4.exe
­