How to remove KMS.exe

KMS.exe

The module KMS.exe has been detected as Hack.KMS

KMS.exe
MD5: 415898f14843d4a6537cf8f43d328eaf
Size: 6 MB
First Published: 2017-05-21 21:04:54 (8 years ago)
Latest Published: 2024-09-29 23:02:17 (11 months ago)
Status: Hack.KMS (on last analysis)
Analysis Date: 2024-09-29 23:02:17 (11 months ago)
Signed By: WZT
Status: Valid
%sysdrive%\windows
%sysdrive%\activators\kmsauto lite portable v1.2.4
%localappdata%\temp
%desktop%\activators+dotnet 4.6.2\kmsauto lite portable v1.2.4
%desktop%\kmsauto lite portable v1.2.4
%sysdrive%\$recycle.bin\s-1-5-21-1123881605-538375082-1153501521-1000\$r67qc13.1\kmsauto lite portable v1.2.4
%desktop%\activators+dotnet 4.6.1\kmsauto lite portable v1.2.4
%desktop%\новая папка (5)\sources\$oem$\$1\activators\kmsauto lite portable v1.2.4
%desktop%\activators\kmsauto lite portable v1.2.4
%profile%\downloads\windows 10 v1703 [15063.447] 32in1 with dart 10 en-hr july 2017 by marbar\_extra_.rar\kmsauto lite portable v1.2.4
KMSAuto.exe
KMS.exe
KMSAuto Net.exe
License.exe
trz38BB.tmp
kmsautolite.exe
gKMSAuto.exe
$RIG46DI.exe
$R828G8P.exe
Russia 35.4%
Ukraine 21.5%
Indonesia 5.5%
Egypt 4.4%
Spain 2.7%
India 2.2%
Thailand 2.1%
Turkey 1.4%
Belarus 1.4%
Philippines 1.4%
Kazakhstan 1.4%
Argentina 1.2%
Pakistan 1.2%
Bangladesh 1.2%
Bulgaria 0.8%
Vietnam 0.7%
Romania 0.7%
Croatia 0.7%
Canada 0.7%
Algeria 0.7%
United Kingdom 0.6%
Moldova 0.6%
Malaysia 0.6%
Mexico 0.6%
France 0.6%
Bolivia 0.6%
Venezuela 0.6%
Denmark 0.4%
Azerbaijan 0.4%
Latvia 0.4%
Saudi Arabia 0.4%
Colombia 0.4%
China 0.4%
Czech Republic 0.4%
Myanmar 0.4%
Italy 0.4%
Peru 0.4%
United States 0.3%
Paraguay 0.3%
South Africa 0.2%
Lithuania 0.2%
Chile 0.2%
Panama 0.1%
Slovakia 0.1%
Austria 0.1%
Slovenia 0.1%
Tunisia 0.1%
Kyrgyzstan 0.1%
Finland 0.1%
Armenia 0.1%
Estonia 0.1%
Poland 0.1%
Morocco 0.1%
Qatar 0.1%
Netherlands 0.1%
Ethiopia 0.1%
Australia 0.1%
Reunion 0.1%
Uganda 0.1%
Switzerland 0.1%
Kenya 0.1%
Former Yugoslav Republic of Macedonia 0.1%
New Zealand 0.1%
Mongolia 0.1%
Germany 0.1%
Brazil 0.1%
Cyprus 0.1%
Palestine 0.1%
Singapore 0.1%
Japan 0.1%
Dominican Republic 0.1%
Greece 0.1%
Nepal 0.1%
Kuwait 0.1%
Serbia 0.1%
Windows 10 52.8%
Windows 7 39.7%
Windows 8.1 6.2%
Windows 8 0.5%
Windows XP 0.2%
Windows Embedded Standard 0.2%
Windows Vista 0.1%
Windows Embedded 8.1 0.1%
Windows Server 2008 R2 0.1%
Windows Server 2016 0.1%
Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x00001000

PE Sections:

Name Size of data MD5
.code 107520 54c77e9f1a7fc471d243b81ddfd3dec7
.text 307200 f1d1dcb82445e9ab9b4b2f73af338172
.rdata 35840 845b07f0ebd235da7031a74ca0534020
.data 6125056 96d46480ffd461719107f0fedc5fa86b
.rsrc 45568 ded747d9d1338903e188cf65f5c929c5

More information:

Download GridinSoft Anti-Malware - Removal tool for KMS.exe
­