How to remove KMS.exe
KMS.exe
The module KMS.exe has been detected as PUP.HackKMS
File Details
Product Name: | KMSAuto Lite |
Company Name: | Ratiborus, MSFree Inc. |
MD5: | 5decf7df696b4456fec4e3a669558995 |
Size: | 1 MB |
First Published: | 2017-07-15 13:06:59 (7 years ago) |
Latest Published: | 2020-09-04 19:49:18 (4 years ago) |
Status: | PUP.HackKMS (on last analysis) | |
Analysis Date: | 2020-09-04 19:49:18 (4 years ago) |
Common Places:
%profile%\downloads\for_officewindows.zip\kmsauto lite portable v1.1.5 |
%windir%\setup\scripts\data |
%sysdrive%\windows |
%localappdata%\temp |
%sysdrive%\activators |
%windir% |
%desktop%\dcp\bonus |
%desktop%\bonus\активация |
%windir%\setup\scripts |
%profile%\егулювання\мои документы\downloads |
File Names:
KMSAuto.exe |
KMS.exe |
KMSAuto.exe.quarantined |
Geography:
62.6% | ||
19.8% | ||
4.4% | ||
3.3% | ||
3.3% | ||
2.2% | ||
1.1% | ||
1.1% | ||
1.1% | ||
1.1% |
OS Version:
Windows 7 | 39.6% | |
Windows 10 | 30.8% | |
Windows 8.1 | 27.5% | |
Windows Embedded 8.1 | 1.1% | |
Windows XP | 1.1% |
Analysis
Subsystem: | Windows GUI |
PE Type: | pe |
OS Bitness: | 32 |
Image Base: | 0x00400000 |
Entry Address: | 0x00001000 |
PE Sections:
Name | Size of data | MD5 |
.code | 91648 | ecade2e45b015112caa484b52975151d |
.text | 307200 | f7dc86cc2e9b8dd27ec8621ccfea2552 |
.rdata | 35840 | 8421f7083bec4fd5e9707a2ebc8d6ed4 |
.data | 1586176 | 3225147ab157a10d32dd5e63c4ed8345 |
.rsrc | 45568 | 1950ef9f1e434bb27c17e57ae4afa330 |
More information:
Download GridinSoft
Anti-Malware - Removal tool for KMS.exe