How to remove KMSELDI_IObitDel.exe
- File Details
- Overview
- Analysis
KMSELDI_IObitDel.exe
The module KMSELDI_IObitDel.exe has been detected as Crack.AutoKMS
File Details
Product Name: |
|
Company Name: |
|
MD5: |
11c05b7138f3a6a3f43bb8f782c8891d |
Size: |
901 KB |
First Published: |
2017-05-21 21:04:38 (7 years ago) |
Latest Published: |
2025-01-26 23:01:54 (2 weeks ago) |
Status: |
Crack.AutoKMS (on last analysis) |
|
Analysis Date: |
2025-01-26 23:01:54 (2 weeks ago) |
Overview
%programfiles%\kmspico |
%programfiles%\activation windows 10 office |
%programfiles%\kmspico2016 |
%appdata%\zhp\quarantine\kmspico |
%sysdrive%\windows.old\program files\kmspico |
%appdata%\zhp\quarantine\kmspico\kmspico |
%programfiles%\office16\kmspico |
%programfiles%\panda security\panda security protection\lostandfound |
%sysdrive%\kmspico |
%programfiles%\microsoft office 15\kmspico |
KMSELDI.exe |
KMSELDI_IObitDel.exe |
trzC03F.tmp |
KMSELDI.exe.quarantined |
|
37.5% |
|
|
5.8% |
|
|
4.0% |
|
|
4.0% |
|
|
3.9% |
|
|
3.9% |
|
|
2.6% |
|
|
2.5% |
|
|
2.5% |
|
|
2.2% |
|
|
2.0% |
|
|
1.6% |
|
|
1.6% |
|
|
1.6% |
|
|
1.5% |
|
|
1.5% |
|
|
1.3% |
|
|
1.2% |
|
|
1.1% |
|
|
1.0% |
|
|
0.9% |
|
|
0.7% |
|
|
0.7% |
|
|
0.7% |
|
|
0.7% |
|
|
0.6% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.4% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
Windows 10 |
66.4% |
|
Windows 7 |
24.7% |
|
Windows 8.1 |
7.8% |
|
Windows 8 |
0.7% |
|
Windows Vista |
0.1% |
|
Windows Server 2012 |
0.1% |
|
Windows Server 2012 R2 |
0.1% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x000dcdfe |
MVID: |
b50cef84-22d1-4211-a072-ef0aba3868e2 |
Name |
Size of data |
MD5 |
.text |
897024 |
8334d6fe6347ce99b96ac4116d9d06a7 |
.rsrc |
20992 |
4827daeb4686598b4738ae8508109e91 |
.reloc |
512 |
8eb1fa85917969846903094220db492d |