How to remove kmsss.exe

kmsss.exe

The module kmsss.exe has been detected as Hack.KMS

kmsss.exe
Product Name:

KMS Server Emulator Service (XP)

Company Name:

MDL Forum, mod by Ratiborus

MD5: 22fc15f2c2e2a77bc5a1186e5f55d7d3
Size: 297 KB
First Published: 2017-05-21 06:07:21 (8 years ago)
Latest Published: 2025-06-20 23:10:40 (2 months ago)
Status: Hack.KMS (on last analysis)
Analysis Date: 2025-06-20 23:10:40 (2 months ago)
Signed By: WZT
Status: Valid
%commonappdata%\kmsautos\bin
%commonappdata%\kmsauto\bin
%appdata%\zhp\quarantine
%windir%\kmsautos\bin
%appdata%\zhp\quarantine\kmsautos\bin
%windir%\kms\bin
%sysdrive%\$recycle.bin\s-1-5-21-257334955-1849367147-1897638829-1000
%windir%\temp\kmsauto\bin
%appdata%\360safe\softmgr\unrulyicon
%sysdrive%\windows.old\programdata\kmsautos\bin
KMSSS.exe
kmsss.exe
$RW1SPW8.exe
105044842.exe
South Korea 18.6%
Russia 15.6%
Ukraine 11.9%
Spain 3.7%
Mexico 3.7%
Iran 3.3%
Egypt 2.9%
Argentina 2.9%
Colombia 2.8%
Vietnam 2.6%
Peru 2.1%
Indonesia 1.6%
Belarus 1.5%
Thailand 1.5%
Turkey 1.3%
Saudi Arabia 1.3%
Ecuador 1.1%
France 1.0%
United States 1.0%
Chile 1.0%
Venezuela 0.9%
Italy 0.7%
Kazakhstan 0.6%
Romania 0.6%
Poland 0.6%
Philippines 0.6%
Czech Republic 0.6%
Bulgaria 0.5%
Algeria 0.5%
Morocco 0.5%
India 0.5%
Malaysia 0.5%
Brazil 0.5%
Belgium 0.5%
Bolivia 0.5%
Guatemala 0.4%
Palestine 0.4%
Iraq 0.4%
Germany 0.4%
Nicaragua 0.4%
United Kingdom 0.3%
Lithuania 0.3%
Canada 0.3%
Latvia 0.3%
Taiwan 0.3%
Panama 0.3%
China 0.3%
Estonia 0.3%
Costa Rica 0.3%
El Salvador 0.3%
Uruguay 0.3%
Netherlands 0.2%
Israel 0.2%
Azerbaijan 0.2%
Tunisia 0.2%
Portugal 0.2%
Jordan 0.2%
Japan 0.2%
Pakistan 0.2%
Greece 0.2%
Georgia 0.2%
Moldova 0.2%
Puerto Rico 0.2%
United Arab Emirates 0.1%
Sweden 0.1%
Paraguay 0.1%
Bahrain 0.1%
Armenia 0.1%
Kyrgyzstan 0.1%
Hong Kong 0.1%
Switzerland 0.1%
Bangladesh 0.1%
Hungary 0.1%
Austria 0.1%
Honduras 0.1%
Dominican Republic 0.1%
Serbia 0.1%
South Africa 0.1%
Windows 10 75.5%
Windows 7 16.2%
Windows 8.1 7.0%
Windows 8 0.8%
Windows Embedded 8.1 0.1%
Windows Server 2008 R2 0.1%
Windows Server 2012 0.1%
Windows Vista 0.1%
Subsystem: Windows CUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x00019164

PE Sections:

Name Size of data MD5
.text 203264 84a6e810c4749f05e143fcc8c329cc58
.rdata 72704 8cbf870fa3734ec4d1cb3f7a2a1c51ef
.data 8192 2006135872ba9899fcb95d86165a4a4c
.rsrc 1536 7ef89e01596af42bac78bea6f205c471
.reloc 14336 5f95ac0361adf44781d483ab0b69e2e6

More information:

Download GridinSoft Anti-Malware - Removal tool for kmsss.exe
­