How to remove KMSELDI_IObitDel.exe
- File Details
- Overview
- Analysis
KMSELDI_IObitDel.exe
The module KMSELDI_IObitDel.exe has been detected as Crack.AutoKMS
File Details
| Product Name: |
|
| Company Name: |
|
| MD5: |
11c05b7138f3a6a3f43bb8f782c8891d |
| Size: |
901 KB |
| First Published: |
2017-05-21 21:04:38 (8 years ago) |
| Latest Published: |
2025-04-23 23:01:07 (6 months ago) |
| Status: |
Crack.AutoKMS (on last analysis) |
|
| Analysis Date: |
2025-04-23 23:01:07 (6 months ago) |
Overview
| %programfiles%\kmspico |
| %programfiles%\activation windows 10 office |
| %programfiles%\kmspico2016 |
| %appdata%\zhp\quarantine\kmspico |
| %sysdrive%\windows.old\program files\kmspico |
| %appdata%\zhp\quarantine\kmspico\kmspico |
| %programfiles%\office16\kmspico |
| %programfiles%\panda security\panda security protection\lostandfound |
| %sysdrive%\kmspico |
| %programfiles%\microsoft office 15\kmspico |
| KMSELDI.exe |
| KMSELDI_IObitDel.exe |
| trzC03F.tmp |
| KMSELDI.exe.quarantined |
|
37.5% |
|
|
5.8% |
|
|
4.0% |
|
|
4.0% |
|
|
4.0% |
|
|
3.9% |
|
|
2.6% |
|
|
2.6% |
|
|
2.5% |
|
|
2.2% |
|
|
2.0% |
|
|
1.6% |
|
|
1.6% |
|
|
1.6% |
|
|
1.5% |
|
|
1.5% |
|
|
1.3% |
|
|
1.2% |
|
|
1.1% |
|
|
1.0% |
|
|
0.9% |
|
|
0.7% |
|
|
0.7% |
|
|
0.7% |
|
|
0.7% |
|
|
0.6% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.4% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
| Windows 10 |
66.4% |
|
| Windows 7 |
24.7% |
|
| Windows 8.1 |
7.8% |
|
| Windows 8 |
0.7% |
|
| Windows Vista |
0.1% |
|
| Windows Server 2012 |
0.1% |
|
| Windows Server 2012 R2 |
0.1% |
|
Analysis
| Subsystem: |
Windows GUI |
| PE Type: |
pe |
| OS Bitness: |
32 |
| Image Base: |
0x00400000 |
| Entry Address: |
0x000dcdfe |
| MVID: |
b50cef84-22d1-4211-a072-ef0aba3868e2 |
| Name |
Size of data |
MD5 |
| .text |
897024 |
8334d6fe6347ce99b96ac4116d9d06a7 |
| .rsrc |
20992 |
4827daeb4686598b4738ae8508109e91 |
| .reloc |
512 |
8eb1fa85917969846903094220db492d |