Gridinsoft Logo
File Icon

KMSTools.exe Crack KMS Analysis

Technical Analysis

File Name KMSTools.exe
File Type
PE32 executable (GUI) Intel 80386, for MS Windows
Scanner Version 1.0.147.174
Database Version 2023-11-20 14:02:37 UTC

Crack.Win32.KMS.vl!c

Malware family: KMS

KMS malware is associated with illegal software activation tools that bypass legitimate licensing mechanisms. It can introduce security vulnerabilities and legal compliance issues.
N/A
Detection Rate
32,982,360
File Size (bytes)
2023-11-20
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
9828f7b373e722da225b8455542b41e8
SHA1
e3512b651c51e187a452a74e3e51651f24d6fdc1
SHA256
b0e5352b737bf904cb50a9e8aaacd88b30b7e35ba344e31dc9298de20146ed9b
SHA512
578ce01609993e402c93bfc03ff554724173b7f08cddd0b8996519d2b2cd3b0acd43bbd2ccdb95440c6e62fc95076d642b216acf0f6299bc0f32bbee8c665f7b
ImpHash
dbab39f0229f5161855ba872bf93162d

PE Analysis

Basic Information

Icon
Hash: 94411a7ac6c8b4bf932b5dac2210f721
Fuzzy: 73da8a07a83dd014e1f1a85021f0cd92
dHash: b848c8f8b8d87426
Image Base 0x00400000
Entry Point 0x00401000
Compilation Time 2018-09-01 04:24:04
Checksum 0x01f7d52c (Actual: 0x01f7d52c)
OS Version 4.0
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
Digital Signature Chain verification from CN=WZTeam (serial:-34590325592400973612903392563650996340, sha1:87b3a6c360b37d6db7f970dd1dc0009fbbd13ba0) failed: The X.509 certificate provided is self-signed - "Common Name: WZTeam"
Imports 22 libraries
Exports 0 functions
Resources 9 Resources
Sections 5 Sections

Digital Signatures

WZTeam ()
UTN-USERFirst-Object COMODO CA Limited (GB)

Version Information

CompanyName Ratiborus
ProductName KMS Tools Portable x86
LegalCopyright Ratiborus
Translation 0x0000 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.code 0x00001000 79,696 bytes 79,872 bytes 5.87 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 5D44321E7BD969DC4ACF8E588FA725A8
.text 0x00015000 467,249 bytes 467,456 bytes 6.61 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 71650CECA4011CC3AB51C27FA204BF52
.rdata 0x00088000 105,188 bytes 105,472 bytes 5.74 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 35D3F1FEFF30240709F6D9A3CE354D8C
.data 0x000a2000 32,221,152 bytes 32,214,528 bytes 7.98 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 0F8EDFC9EFE1774CBF52E4281E10330C
.rsrc 0x01f5d000 107,368 bytes 107,520 bytes 7.72 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 5B4CDA1E1040417C4775900CF4C39A9C
Entropy Analysis Alert

2 section(s) with high entropy (≥7.5) detected - possible packing/encryption

1 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 9 (106,814 bytes)
Resource Type Count Total Size Percentage
RT_ICON 6 105,502 bytes
98.8%
RT_GROUP_ICON 1 90 bytes
0.1%
RT_VERSION 1 408 bytes
0.4%
RT_MANIFEST 1 814 bytes
0.8%

Certificate Chain Analysis

Certificate #1
Subject WZTeam
Issuer WZTeam
Serial Number -155843482902537470358085606074993314206
Certificate #2
Subject COMODO SHA-1 Time Stamping Signer
COMODO CA Limited
GB
Issuer UTN-USERFirst-Object
Serial Number 117007971038687812527568897756771083
Certificate Verification Status

Chain verification from CN=WZTeam (serial:-34590325592400973612903392563650996340, sha1:87b3a6c360b37d6db7f970dd1dc0009fbbd13ba0) failed: The X.509 certificate provided is self-signed - "Common Name: WZTeam"

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Crack.Win32.KMS.vl!c Removal

Gridinsoft has the capability to identify and eliminate Crack.Win32.KMS.vl!c without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware
An unexpected error occurred. Please try again later.