How to remove KMSELDI.exe
- File Details
- Overview
- Analysis
KMSELDI.exe
The module KMSELDI.exe has been detected as Hack.KMS
File Details
Product Name: |
|
Company Name: |
|
MD5: |
738bc9c893c3bd7cd6052ac3ee2707e7 |
Size: |
1 MB |
First Published: |
2017-05-30 18:11:44 (7 years ago) |
Latest Published: |
2020-10-08 12:03:47 (4 years ago) |
Status: |
Hack.KMS (on last analysis) |
|
Analysis Date: |
2020-10-08 12:03:47 (4 years ago) |
%programfiles%\kmspico |
%programfiles% |
%sysdrive% |
%programfiles% |
%programfiles% |
%programfiles% |
|
23.7% |
|
|
13.2% |
|
|
10.5% |
|
|
10.5% |
|
|
7.9% |
|
|
5.3% |
|
|
5.3% |
|
|
5.3% |
|
|
2.6% |
|
|
2.6% |
|
|
2.6% |
|
|
2.6% |
|
|
2.6% |
|
|
2.6% |
|
|
2.6% |
|
Windows 7 |
41.0% |
|
Windows 10 |
33.3% |
|
Windows 8 |
12.8% |
|
Windows 8.1 |
5.1% |
|
Windows Server 2008 R2 |
5.1% |
|
Windows Vista |
2.6% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x000d8d6e |
MVID: |
cfd1d97b-8dc7-40bf-b41e-e07051fab278 |
Typelib ID: |
863d9135-9365-4bee-95bf-0d83ded34d9f |
Name |
Size of data |
MD5 |
.text |
880128 |
046f04c8bc4af8de1367a12b4990bd85 |
.sdata |
512 |
1ce061e77c10fa37a9f7c950f48f081d |
.rsrc |
374272 |
99a76b7b9e0cd9fa413774b626af8327 |
.reloc |
512 |
0591e53102e3362291ea6196c970c0a2 |