How to remove PIDKey.exe

PIDKey.exe

The module PIDKey.exe has been detected as Hack.KMS

PIDKey.exe
Product Name:

PIDKey

Company Name:

MSfree Inc. (Ratiborus and friends)

MD5: 5690451331ea258f1edf5707e86a7e7a
Size: 2 MB
First Published: 2017-05-30 05:13:07 (6 years ago)
Latest Published: 2019-08-06 17:08:36 (4 years ago)
Status: Hack.KMS (on last analysis)
Analysis Date: 2019-08-06 17:08:36 (4 years ago)
Signed By: Ratiborus MSFree Inc.
Status: Valid
%temp%\rar$exa0.405\pidkey v2.0.9.1004
%temp%\rar$exa0.069\pidkey v2.0.9.1004
%profile%\downloads\compressed\pidkey v2.0.9.1004
%sysdrive%\new folder
%sysdrive%\c_archive\активатор для windows 7\pidkey v2.0.9.1004
%temp%
%temp%\rar$exa0.590
%temp%\rar$exa0.486
%sysdrive%\soft linh tinh\check key microsoft\pidkey v2.0.9.1004
%sysdrive%\sandisk64\utilities
31.6%
21.1%
15.8%
10.5%
10.5%
5.3%
5.3%
Windows 10 42.1%
Windows 8.1 31.6%
Windows 7 26.3%
Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x0029a6e6

.NET Info:

MVID: 38564938-7bc8-49c0-97a2-dcaedf3e3695
Typelib ID: 966f2f24-866c-4ddd-9678-ec3427ac80f5

PE Sections:

Name Size of data MD5
.text 2721792 28659bd5a82265201264b85ae9255a67
.rsrc 72704 2bc2a1f0d3b42cad55c5109a0af83b9f
.reloc 512 43f628ee69a08f3a57ee9f592fa6ad51

More information:

Download GridinSoft Anti-Malware - Removal tool for PIDKey.exe