How to remove HEU_KMS.exe
- File Details
- Overview
- Analysis
HEU_KMS.exe
The module HEU_KMS.exe has been detected as Ransom.Wacatac
File Details
Product Name: |
|
Company Name: |
|
MD5: |
46a752ebddbfb9178b336c4b968d8d23 |
Size: |
4 MB |
First Published: |
2024-03-09 23:02:28 (a year ago) |
Latest Published: |
2025-01-07 23:07:10 (6 months ago) |
Status: |
Ransom.Wacatac (on last analysis) |
|
Analysis Date: |
2025-01-07 23:07:10 (6 months ago) |
%sysdrive%\全能pc端激活工具heukmsactivator v42.0.1 |
%sysdrive%\压缩软件\全能pc端激活工具heukmsactivator v42.0.1.7z |
%profile%\downloads\morphs_installs_april_2024-teamos\morphs_installs_april_2024-teamos\installs |
%desktop%\heu kms activator 42.0.1 |
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x0051dd80 |
Name |
Size of data |
MD5 |
UPX0 |
0 |
d41d8cd98f00b204e9800998ecf8427e |
UPX1 |
381440 |
e88f78eb2b0c0d4ab8c3d24e74bc7981 |
.rsrc |
4428288 |
6c6b1403d6effde292f1f47aa069ce46 |