How to remove OInstall.exe

OInstall.exe

The module OInstall.exe has been detected as Hack.KMS

OInstall.exe
Product Name:

Office 2013-2016 C2R Install

MD5: c952a888e6e03a4394b8b09549d78ee1
Size: 13 MB
First Published: 2018-08-02 07:07:57 (5 years ago)
Latest Published: 2020-01-05 05:01:14 (4 years ago)
Status: Hack.KMS (on last analysis)
Analysis Date: 2020-01-05 05:01:14 (4 years ago)
Signed By: WZTeam
Status: Invalid (digital signature could be stolen or file could be patched)
%sysdrive%\downloads\### - software\office_2013-2016_c2r_5.9.9.sanet.cd.rar\office_2013-2016_c2r_install_v5.9.9
%sysdrive%\downloads\microsoft toolkit collection pack november 2017-p2p\microsoft.toolkit.collection.pack.november.2017-p2p\microsoft.toolkit.collection.pack.november.2017-p2p
%sysdrive%\programas fotos android\programas\microsoft toolkit collection pack agosto 2017\programas
%sysdrive%\программы\beloff_2017.8\apps\!microsoft\kms
%sysdrive%\prog\2017\office\of16.aug.x64\microsoft-toolkit-collection-pack-july-2017.rar\microsoft toolkit collection pack july 2017\july2017\july2017
%desktop%\activation
%profile%\downloads\c2r
%desktop%\orden 5326\desktop\oninstall
%sysdrive%\.distrib\windows\microsoft toolkit collection pack
%windir%
31.0%
3.4%
3.4%
3.4%
3.4%
3.4%
3.4%
3.4%
3.4%
3.4%
3.4%
3.4%
3.4%
3.4%
3.4%
3.4%
3.4%
3.4%
3.4%
3.4%
3.4%
Windows 10 72.4%
Windows 7 24.1%
Windows 8.1 3.4%
Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x00001000

PE Sections:

Name Size of data MD5
.code 140800 ab2288607d3509799a7e17de67e7549f
.text 743936 11644e999a0f8f792e4b0a05d9fe4b6e
.rdata 143872 6cc4ce09a38053ff0c45ad6a6787bea6
.data 12615680 dd96d5932c50bcf963c45ecc1674c6f4
.rsrc 84480 b1ed15fcc242420b2a6b80a6132ee068
.modplug 0 00000000000000000000000000000000

More information:

Download GridinSoft Anti-Malware - Removal tool for OInstall.exe