RMS file reports

RMS

RMS is a product name observed in ThreatInfo file telemetry. This page groups the latest 60 files that reference this product name, including their detection status and direct file reports.

Review the listed files before removing anything: legitimate software can share product names with unwanted or repacked installers, while malicious files often reuse familiar product metadata to appear trustworthy.

Scan files associated with RMS:

Offline eBIRForms Package v7.9 4f0135fb0cb578496c656cf8b0322a35 Ransom.Wacatac
e1rmsg.dll 537e23b371c5301909ff26faafd16b19 Under review
E1RMSG.DLL bff734b01fe75e83e6a683d88b1fe581 Clean
AuWsRMsg.exe 27033451f9c8f84364c67b6fb4408dcf PUP.MaxSecureSoftware
wwp.exe 4d53bf702861ad6ba06627c8c09722a9 General Threat
Setup.exe 396b0aa1c59dc92ce60d66604bdf08de General Threat
WormsReloaded.exe c4f788fedc9dfd0129cc333828f77dcc Trojan.Heur!
wa.exe c6def1871f5da553bd24915d87f90a1e General Threat
bestzx.exe 1c8364e2d75df23d8fe494b0fabe439b Ransom.Sabsik
WindowsFormsIntegration.dll ff3c1f18d4f1cf8987ad4be53d72c780 Under review
WindowsFormsIntegration.dll 90544d4d0b62647b4e1799804d78a351 Under review
WindowsFormsIntegration.dll b075e42730722c20207cd29a3960ab0f Under review
WindowsFormsIntegration.dll 0a90d6f7745945ac8b4ab943117a2997 Under review
WindowsFormsIntegration.dll 26139853a0a406e26aa3afcabf9615b9 Under review
WindowsFormsIntegration.dll 657eefe7dfd456a52c47613771cb7652 Risk.CoinMiner
WindowsFormsIntegration.dll e0762a0a4df7b89dc12656d44730b3f0 Risk.CoinMiner
WindowsFormsIntegration.dll 6dc2f76d436505026698aff7cd7a1b60 Under review
WindowsFormsIntegration.dll f6b19e8c0387992c46535dea9bd049f3 Under review
MULTI EDITOR TOOL BY DR SALEH. f8967aa7ff6d13528d36d726eec9487c Trojan.Packed
MULTI EDITOR - By Dr.Saleh V2 5d0e4cba6079c65df6a56e7004981612 Trojan.Heur!
AXS.exe 790bb589d9d8ef8813367851ffc6418a General Threat
svchost..exe af395a20ce108745fdb19e5d91debd02 Trojan.Agent
suchost..exe b6404da30cc21b244a101b0a23a14709 Trojan.Agent
_Slt.exe 057201048cfbe832632b44162d23eeed Trojan.Agent
Action.exe 0f42d9c145c13ef0ef04952715f98933 Trojan.Agent
svchost..exe f9d72e2d4427fb93c36913e30dbb1cd7 Trojan.Gen
ReportDesigner.exe 65ee87dcb42abf6da9feb5c018acadda Trojan.Agent
boot.exe 4e73ce96c0ffed95feab7d53f098b0bb Trojan.Agent
svchost..exe 1713c03963faddee5206eec36b193c45 General Threat
eba2a7a9c4a6c3a2c3f04431312a94 52119e15b34b2908550bad2e441db454 Ransom.Wacatac
9b33661773d15950915dc3344a428e c88f557c9e9935393805e83a7d429838 Trojan.Packed
f472a9f82e1779fa913f345d0fc4a5 be0fe09341b85122377ec2b46791d5e1 Trojan.AgentTesla
SSH Scan.exe 1e58f5fd1cd0becbe8a98dfd3366164f Trojan.Gen
Auto Reg Coin.exe 358a5d7c1dae2fe28eed2af5baccb9ed Trojan.Gen
system32.exe 3d652375fd511878f410fb1048e47f83 Trojan.Agent
very important.exe af048f598f63a6b8cc4ec942f2f5472a Trojan.Agent
system32.exe fa5acb17cd9c90d0f765cada71194c7d Trojan.Agent
EiBypass.exe ddedf2b84e40c26c4266410d7e57bdde Suspicious Object
615b9cfb19070c6aa8ec0f8a801473 303cea223e16a4649cad0d2130262997 Trojan.Kryptik
9fcf0a498b86fc20af3cc28a984135 c3c291b38d054d5e71fe17a10d737249 Trojan.Kryptik
dcb42fb2487eeee3ad0a36b6dd2b6f 6d62ef994bf72f5ca8fbc72b6ef798af Adware.Linkury
94e41741803ebfe3ef088e4f0d8677 24f3fff5016853f4c85546d338ade05a General Threat
d5387c42e8059092e86b896c525002 2414aab964b19e19cb8b57ccc6b3e6c3 Trojan.Packed
NDownloader.exe 1d1d3abd09b328049b432d6a334cdfd7 General Threat
ForceBindIP GUIv1.5.exe f32aa48b1b0660b5a65b25220686b892 Trojan.Agent
WindowsFormsApplication1.exe 596ddb55719f99235422bb1eafbcba73 General Threat
zzzz.exe 0dcdfda5571420f7636ae33fba985dec Suspicious Object
changeresolution.exe 1ae054c5a76e117279337afeec52a62f General Threat
8dbcffd97d94be3165aec10026ea00 51a387b9b5f5c0645f72573bf175f9ef Ransom.LokiBot
02ee87012effdfa84c909b301c1c99 0858268f3b83634a182ae13cce53ad86 Spy.Gen
smss.exe 3e0008cc2c154ed7421566bfbcef4c1b Ransom.Blocker
Qekdqa.exe 6639386657759bdac5f11fd8b599e353 Trojan.Kryptik
menu.exe ce2c0ed304b2b56b17b0b839c2537f44 Possible Threat
Windows Defender.exe 90ba6cbb9461cf91dc32038a739287a1 Trojan.Heur!
WindowsFormsApp3.exe b83a250543325d130f61b217e3e15d7d Trojan.Kryptik
WindowsFormsApp3.exe 702bfeb377c3d1e380997049dfaab64b Trojan.Kryptik
66118056838724228164.exe c0733366f99c2f15e2187eb2e0798514 Trojan.Kryptik
WindowsFormsApp3.exe dc9e0182dacf8b3e9f307ce2b74db873 Trojan.Kryptik
WindowsFormsApp3.exe 8414200c4fcf3765d3f47b32e9e457a0 Trojan.Kryptik
WindowsFormsApp3.exe 4dc7d55a47a5af7af1d9f1d8b81a6819 Trojan.Kryptik