How to remove kmsss.exe

kmsss.exe

The module kmsss.exe has been detected as Hack.KMS

kmsss.exe
Product Name:

KMS Server Emulator Service (XP)

Company Name:

MDL Forum, mod by Ratiborus

MD5: 22fc15f2c2e2a77bc5a1186e5f55d7d3
Size: 297 KB
First Published: 2017-05-21 06:07:21 (7 years ago)
Latest Published: 2024-10-23 23:01:03 (2 months ago)
Status: Hack.KMS (on last analysis)
Analysis Date: 2024-10-23 23:01:03 (2 months ago)
Signed By: WZT
Status: Valid
%commonappdata%\kmsautos\bin
%commonappdata%\kmsauto\bin
%appdata%\zhp\quarantine
%windir%\kmsautos\bin
%appdata%\zhp\quarantine\kmsautos\bin
%windir%\kms\bin
%sysdrive%\$recycle.bin\s-1-5-21-257334955-1849367147-1897638829-1000
%windir%\temp\kmsauto\bin
%appdata%\360safe\softmgr\unrulyicon
%sysdrive%\windows.old\programdata\kmsautos\bin
KMSSS.exe
kmsss.exe
$RW1SPW8.exe
105044842.exe
18.6%
15.7%
12.0%
3.7%
3.7%
3.3%
3.0%
2.9%
2.8%
2.6%
1.9%
1.6%
1.5%
1.5%
1.3%
1.3%
1.1%
1.0%
1.0%
1.0%
0.9%
0.7%
0.7%
0.7%
0.7%
0.6%
0.6%
0.5%
0.5%
0.5%
0.5%
0.5%
0.5%
0.5%
0.5%
0.4%
0.4%
0.4%
0.4%
0.4%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.2%
0.2%
0.2%
0.2%
0.2%
0.2%
0.2%
0.2%
0.2%
0.2%
0.2%
0.2%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
Windows 10 75.5%
Windows 7 16.2%
Windows 8.1 7.1%
Windows 8 0.8%
Windows Embedded 8.1 0.1%
Windows Server 2008 R2 0.1%
Windows Server 2012 0.1%
Windows Vista 0.1%
Subsystem: Windows CUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x00019164

PE Sections:

Name Size of data MD5
.text 203264 84a6e810c4749f05e143fcc8c329cc58
.rdata 72704 8cbf870fa3734ec4d1cb3f7a2a1c51ef
.data 8192 2006135872ba9899fcb95d86165a4a4c
.rsrc 1536 7ef89e01596af42bac78bea6f205c471
.reloc 14336 5f95ac0361adf44781d483ab0b69e2e6

More information:

Download GridinSoft Anti-Malware - Removal tool for kmsss.exe