How to remove $RSAR30Z.exe

$RSAR30Z.exe

The module $RSAR30Z.exe has been detected as Hack.KMS

$RSAR30Z.exe
Product Name:

UniCrypt

MD5: cb365afebc5ae02916b6a9c7bacb9d70
Size: 1 MB
First Published: 2017-09-09 11:13:46 (7 years ago)
Latest Published: 2021-02-26 04:59:01 (3 years ago)
Status: Hack.KMS (on last analysis)
Analysis Date: 2021-02-26 04:59:01 (3 years ago)
Signed By: WZT
Status: Valid
%desktop%\kms tools portable 07_06_2016\programs\unicrypt 2016 v2.2
%mydoc%\programs to keep\aktivator!!!\kms tools portable 06_08_2016_\programs\unicrypt 2016 v2.2
%desktop%\from lyamine\kms tools portable 06.12.2016\kms tools portable 06.12.2016\programs
%desktop%\from lyamine\kms tools portable 06.12.2016\programs
%profile%\downloads\kms tools portable 01.11.2016 by ratiborus\programs
%sysdrive%\admin\ratiborus\programs
%desktop%\aktivator!!!\kms tools portable 06_08_2016_\programs
%desktop%\aktivator!!!\kms tools portable 06_08_2016_\programs\pidkey v2.1.2.1015\kms tools portable 06_08_2016_\programs
%profile%\downloads\kms tools portable 01.11.2016\programs
%profile%\downloads\compressed\ratiborus.kms.tools.01.11.2016\ratiborus.kms.tools.01.11.2016\programs
UniCrypt_x64.exe
$RSAR30Z.exe
13.3%
13.3%
10.0%
10.0%
6.7%
6.7%
6.7%
6.7%
3.3%
3.3%
3.3%
3.3%
3.3%
3.3%
3.3%
3.3%
Windows 10 56.7%
Windows 7 36.7%
Windows 8.1 3.3%
Windows Embedded 8.1 3.3%
Subsystem: Windows GUI
PE Type: pe
OS Bitness: 64
Image Base: 0x0000000140000000
Entry Address: 0x00001000

PE Sections:

Name Size of data MD5
.code 152064 6ef6a5b0a499d25cc7e326aaba24c91e
.text 460800 ddaa89bb65f4ddc0331664de88ac1dc8
.rdata 84992 978019fb07665c25a871edbeb6732710
.pdata 24576 3d97d3c603a368f5080eed486cb7f88b
.data 172032 6a356971b95543c413a7a593b616e2aa
.rsrc 1132544 2d41e275ec44133fd1bc6e2c3bfaedc9

More information:

Download GridinSoft Anti-Malware - Removal tool for $RSAR30Z.exe