How to remove pidkey.exe
pidkey.exe
The module pidkey.exe has been detected as Hack.KMS
File Details
Product Name: | PIDKey |
Company Name: | MSfree Inc. (Ratiborus and friends) |
MD5: | 0d092cf08de190620aafae7dbb3ffff7 |
Size: | 3 MB |
First Published: | 2017-09-03 10:09:35 (7 years ago) |
Latest Published: | 2020-12-30 19:18:22 (4 years ago) |
Status: | Hack.KMS (on last analysis) | |
Analysis Date: | 2020-12-30 19:18:22 (4 years ago) |
Overview
Signed By: | Ratiborus MSFree Inc. |
Status: | Invalid (digital signature could be stolen or file could be patched) |
Common Places:
%desktop%\pidkey v2.0.9.1005 |
%sysdrive%\systems\windows_7_sp1_with_last_updates_by_kottosoft_32bit_64bit_2016_ukr\bonus\створити папку |
%sysdrive%\microsoft toolkit collection pack november 2015\microsoft toolkit collection pack november 2015\pidkey.2.0.9.1005.zip |
%sysdrive%\filehistory\suen\suence\data\c\users\suen\documents\jdown\mtcp nov\mtcp.nov.2015 |
File Names:
PIDKey.exe |
pidkey.exe |
Geography:
16.7% | ||
16.7% | ||
16.7% | ||
16.7% | ||
16.7% | ||
16.7% |
OS Version:
Windows 10 | 50.0% | |
Windows 7 | 33.3% | |
Windows 8.1 | 16.7% |
Analysis
Subsystem: | Windows GUI |
PE Type: | pe |
OS Bitness: | 32 |
Image Base: | 0x00400000 |
Entry Address: | 0x00345ca6 |
PE Sections:
Name | Size of data | MD5 |
.text | 3423744 | f33c0fef8e9381f9e7b4f2717ba27477 |
.rsrc | 72704 | 8713e8a9a3eade1b43e82e8fa07a08f1 |
.reloc | 512 | 2416933287d95a42a0490e026308e914 |
More information:
Download GridinSoft
Anti-Malware - Removal tool for pidkey.exe