How to remove KMS.exe
KMS.exe
The module KMS.exe has been detected as Hack.KMS
File Details
MD5: | 03530be914b909dcda91714a1134ac68 |
Size: | 6 MB |
First Published: | 2017-05-24 19:11:33 (7 years ago) |
Latest Published: | 2020-10-13 11:31:34 (4 years ago) |
Status: | Hack.KMS (on last analysis) | |
Analysis Date: | 2020-10-13 11:31:34 (4 years ago) |
Overview
Signed By: | WZT |
Status: | Valid |
Common Places:
%sysdrive%\windows |
%localappdata%\temp |
%windir% |
%sysdrive%\ahmet |
%temp%\temp1_kmsauto lite 1.2.8 portable.zip\kmsauto lite 1.2.8 portable |
%windir%\setup\scripts\activator |
%sysdrive%\sources\1.simphony\new folder |
%sysdrive% |
%temp% |
%sysdrive%\zona downloads |
File Names:
KMSAuto.exe |
KMS.exe |
Geography:
42.4% | ||
24.3% | ||
5.6% | ||
4.9% | ||
4.2% | ||
4.2% | ||
2.8% | ||
2.8% | ||
2.1% | ||
1.4% | ||
1.4% | ||
0.7% | ||
0.7% | ||
0.7% | ||
0.7% | ||
0.7% | ||
0.7% |
OS Version:
Windows 10 | 58.7% | |
Windows 7 | 34.0% | |
Windows Embedded 8.1 | 3.3% | |
Windows 8.1 | 2.0% | |
Windows 8 | 1.3% | |
Windows Server 2008 R2 | 0.7% |
Analysis
Subsystem: | Windows GUI |
PE Type: | pe |
OS Bitness: | 32 |
Image Base: | 0x00400000 |
Entry Address: | 0x00001000 |
PE Sections:
Name | Size of data | MD5 |
.code | 114688 | 738f3460104d4b8cff28148746766678 |
.text | 360448 | 02234ccade8a1070aebc721eaa4967a6 |
.rdata | 37888 | e6187ad982d9d7967a02a7f08bebbfe5 |
.data | 6262272 | b0a6a1d1ed8d986b75d9e33763cd7e9e |
.rsrc | 45568 | dd7e1b64692fa3600fd354c59adc5b2b |
More information:
Download GridinSoft
Anti-Malware - Removal tool for KMS.exe