Crack

AutoKMS.HackTool.Patcher.DDS removal guide

Malware Removal

The AutoKMS.HackTool.Patcher.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AutoKMS.HackTool.Patcher.DDS virus can do?

  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Detects the presence of Wine emulator via function name
  • Queries information on disks, possibly for anti-virtualization
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Collects information about installed applications
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

Related domains:

dimgobi.top
strangerthingz.club

How to determine AutoKMS.HackTool.Patcher.DDS?


File Info:

crc32: 43038E31
md5: 43d078d6b7270dee9cbb030680cdc4c1
name: 43D078D6B7270DEE9CBB030680CDC4C1.mlw
sha1: 2b2e4119b24bac7a77c413f275959201cd7a9cc2
sha256: dcaefb28811df3060113ec6b97e714856a41ed52fa0681a977512808582a697c
sha512: 2046d6eeb3906c3f1c5d54583c0af2dfbb61f4853cbd79b828158ee5c2aeadd4ce8dd32acaee5b339a6979d39c7b7b03643c2f662e86067aea74b25aa9d4fcfe
ssdeep: 49152:TkRms5u0uik0FvuVj7jxqkeUWyq9tdemaD9mGCKidCwxoyXOSRsj0Zuur1T75YBq:TGnu0uis+9f9OdJg1wrmNXyVvcj
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: Windows app
FileVersion: 5.9.12.11
Comments: Windows app v.5
ProductName: Windows app
ProductVersion: 5.9.12.11
FileDescription: Windows app
Translation: 0x0409 0x04e4

AutoKMS.HackTool.Patcher.DDS also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Application.InstallMonster.1
FireEyeGeneric.mg.43d078d6b7270dee
CAT-QuickHealAdware.InstallMonster.A8
Qihoo-360Win32/Application.64a
ALYacGen:Application.InstallMonster.1
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
K7AntiVirusTrojan ( 0051ba921 )
BitDefenderGen:Application.InstallMonster.1
K7GWTrojan ( 0051ba921 )
Cybereasonmalicious.6b7270
BitDefenderThetaAI:Packer.630AE8B020
CyrenW32/Trojan.DXS.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of Win32/InstallMonstr.UD potentially unwanted
APEXMalicious
AvastWin32:Adware-gen [Adw]
ClamAVWin.Malware.Agent-6598770-0
NANO-AntivirusTrojan.Win32.InstallMonster.euxpvo
TencentMalware.Win32.Gencirc.10b44471
Ad-AwareGen:Application.InstallMonster.1
EmsisoftGen:Application.InstallMonster.1 (B)
ComodoApplication.Win32.InstallMonster.TN@7g2wfa
F-SecureAdware.ADWARE/InstMonster.Gen7
DrWebTrojan.InstallMonster.2398
ZillyaTool.InstallMonster.Win32.206
TrendMicroHT_INSTALLMONSTER_GK060036.UVPM
McAfee-GW-EditionBehavesLike.Win32.AdwareIMonster.wc
SophosInstall Monster (PUA)
SentinelOneStatic AI – Malicious PE – Installer
AviraADWARE/InstMonster.Gen7
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftSoftwareBundler:Win32/InstallMonster
ArcabitApplication.InstallMonster.1
AhnLab-V3PUP/Win32.InstallMonster.R214848
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Application.InstallMonstr.V
CynetMalicious (score: 100)
Acronissuspicious
McAfeePUP-GQJ
MAXmalware (ai score=79)
VBA32BScope.Adware.DLBoost
MalwarebytesAutoKMS.HackTool.Patcher.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallHT_INSTALLMONSTER_GK060036.UVPM
RisingAdware.InstallMonstr!1.A3B8 (CLASSIC)
YandexTrojan.GenAsa!t8apQkxRoxY
IkarusAdWare.BundleApp
eGambitUnsafe.AI_Score_99%
FortinetRiskware/InstallMonstr
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove AutoKMS.HackTool.Patcher.DDS?

AutoKMS.HackTool.Patcher.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment