How to remove KMSELDI.exe.vir

KMSELDI.exe.vir Removal: How to Get Rid of KMSELDI.exe.vir6bbedd3e5505afa3c9ce2b81a0c1362d

KMSELDI.exe.vir

The module KMSELDI.exe.vir has been detected as Hack.KMS

KMSELDI.exe.vir
Product Name:

KMS GUI ELDI

MD5: 6bbedd3e5505afa3c9ce2b81a0c1362d
Size: 1 MB
First Published: 2017-05-21 06:07:16 (2 years ago)
Latest Published: 2019-08-10 16:51:29 (12 days ago)
Status: Hack.KMS (on last analysis)
Analysis Date: 2019-08-10 16:51:29 (12 days ago)
Signed By: @ByELDI
Status: Valid
%programfiles%\kmspico
%appdata%\zhp\quarantine\kmspico
%programfiles%\panda security\panda security protection\lostandfound
%programfiles%
%desktop%\desktop
%desktop%
%programfiles%\panda security\panda security protection
%sysdrive%\$recycle.bin\s-1-5-21-1705778768-239233795-1564717606-1001
%sysdrive%\windows.old\program files
%desktop%\spico
KMSELDI.exe
KMSELDI.exe.vir
16.2%
12.8%
10.1%
6.8%
4.5%
3.6%
3.4%
3.1%
2.5%
2.3%
2.2%
2.2%
1.8%
1.8%
1.6%
1.4%
1.4%
1.3%
1.3%
1.1%
1.1%
0.9%
0.9%
0.9%
0.7%
0.7%
0.7%
0.7%
0.7%
0.7%
0.7%
0.7%
0.5%
0.5%
0.5%
0.5%
0.5%
0.5%
0.5%
0.5%
0.4%
0.4%
0.4%
0.4%
0.4%
0.4%
0.2%
0.2%
0.2%
0.2%
0.2%
0.2%
0.2%
0.2%
0.2%
0.2%
0.2%
0.2%
0.2%
0.2%
0.2%
Windows 8.1 38.0%
Windows 7 31.4%
Windows 10 25.8%
Windows 8 2.7%
Windows Server 2008 R2 1.2%
Windows Server 2012 R2 0.4%
Windows Embedded 8.1 0.4%
Windows Vista 0.2%
Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x0010774e

.NET Info:

MVID: 858763be-b485-49fe-bd97-0e5a4a38be6b

PE Sections:

Name Size of data MD5
.text 1071104 52c797e52d382dad4334e2d4e7517761
.sdata 512 576c4293c24890c7b0d1d0e333d55730
.rsrc 20992 63424a2815c8919d2d6b6f2f61ae98a9
.reloc 512 a8d3351b914f0963aa7c031c1ee9fa31

More information:

Download GridinSoft Anti-Malware - Removal tool for KMSELDI.exe.vir