How to remove kmseldi.exe
- File Details
- Overview
- Analysis
kmseldi.exe
The module kmseldi.exe has been detected as Hack.KMS
File Details
Product Name: |
|
MD5: |
f9920eb356157477c001e83641c9a97d |
Size: |
803 KB |
First Published: |
2017-05-24 19:10:12 (7 years ago) |
Latest Published: |
2021-01-14 18:49:05 (3 years ago) |
Status: |
Hack.KMS (on last analysis) |
|
Analysis Date: |
2021-01-14 18:49:05 (3 years ago) |
Overview
%programfiles%\kmspico |
%programfiles%\activation windows 8 office 2013 |
%programfiles% |
%sysdrive%\programas |
%appdata%\zhp\quarantine\zhpcleaner |
%sysdrive% |
%appdata%\360safe\softmgr |
%programfiles% |
%programfiles% |
%programfiles% |
KMSELDI.exe |
kmseldi.exe |
104700748.exe |
|
43.1% |
|
|
11.5% |
|
|
11.0% |
|
|
6.0% |
|
|
5.5% |
|
|
4.1% |
|
|
3.2% |
|
|
2.3% |
|
|
2.3% |
|
|
0.9% |
|
|
0.9% |
|
|
0.9% |
|
|
0.9% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
Windows 8.1 |
50.0% |
|
Windows 7 |
27.7% |
|
Windows 10 |
21.8% |
|
Windows 8 |
0.5% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x000c496e |
MVID: |
30eaec81-5328-40de-a08c-4d8e9ed03ece |
Typelib ID: |
863d9135-9365-4bee-95bf-0d83ded34d9f |
Name |
Size of data |
MD5 |
.text |
797184 |
b03dd10d878587b8f56e043f34b793d8 |
.sdata |
512 |
a339c1be53501a20b3cc7dbf2b2ca0c3 |
.rsrc |
20992 |
bc8b5fdfa8c1c4700f35d46addf533c9 |
.reloc |
512 |
dd7f06fe9bae51026879ae7b2fc93515 |