How to remove KMS-R@1nHook.exe

KMS-R@1nHook.exe

The module KMS-R@1nHook.exe has been detected as Hijack.Explorer

KMS-R@1nHook.exe
MD5: dc30cfd21bbb742c10e3621d5b506780
Size: 5 KB
First Published: 2017-05-22 02:09:49 (8 years ago)
Latest Published: 2025-06-21 23:01:22 (2 months ago)
Status: Hijack.Explorer (on last analysis)
Analysis Date: 2025-06-21 23:01:22 (2 months ago)
%sysdrive%\windows
%windir%
%commonappdata%
%windir%
%windir%
%windir%
%windir%
%windir%
%windir%
%windir%
kms-r@1nhook.exe
KMS-R@1nHook.exe
SppSvc.exe|Debugger "kms-r@1nhook.exe"
OSPPSVC.EXE|Debugger "kms-r@1nhook.exe"
KMS-R@1nHook.exe.q_Quarantine_2CF1400_q
Turkey 26.7%
Brazil 25.6%
Thailand 10.3%
Egypt 5.1%
Poland 4.6%
United Kingdom 3.1%
United States 2.1%
France 2.1%
Indonesia 1.5%
Serbia 1.5%
Myanmar 1.5%
undefined 1.5%
Jordan 1.5%
Malaysia 1.5%
Vietnam 1.5%
Taiwan 1.5%
Saudi Arabia 1.5%
Italy 1.0%
Sudan 1.0%
Peru 1.0%
Algeria 1.0%
Belarus 0.5%
Ukraine 0.5%
Azerbaijan 0.5%
Philippines 0.5%
Seychelles 0.5%
Windows 10 78.5%
Windows 7 15.5%
Windows 8 3.0%
Windows 8.1 2.0%
Windows Server 2012 R2 1.0%
Subsystem: Windows GUI
PE Type: pe
OS Bitness: 64
Image Base: 0x0000000140000000
Entry Address: 0x00001000

PE Sections:

Name Size of data MD5
.text 1024 08fd87cd603cacb937d77c18ca840599
.rdata 2048 4c71b5b7b9971c874ad9d84663d83c99
.pdata 512 4d52547da925fd74661b0902c0f65209
.rsrc 512 8d096de51d16180d98ba04bad2632f19

More information:

Download GridinSoft Anti-Malware - Removal tool for KMS-R@1nHook.exe
­