Crack

Should I remove “HackTool.Win32.KMSAuto.i”?

Malware Removal

The HackTool.Win32.KMSAuto.i is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What HackTool.Win32.KMSAuto.i virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine HackTool.Win32.KMSAuto.i?


File Info:

name: 7A596F43E30C04B044A1.mlw
path: /opt/CAPEv2/storage/binaries/c0f05ae32ba4b8ecaebf95c1b02eb15d8b7b0379d221af7e9b6733f6feecf9a0
crc32: 20FC8824
md5: 7a596f43e30c04b044a172b6f859dfd5
sha1: 54780a4b890b8eed1195c07c51cf7afe056717d1
sha256: c0f05ae32ba4b8ecaebf95c1b02eb15d8b7b0379d221af7e9b6733f6feecf9a0
sha512: 1db86b3e65fc68b497423e573e1711862927701a18e77c5cc4752ebec4a2607c55186df63eeb0529afd7583ca643340dc6e3be13eeaf07bb74e1bc7c0ea882cf
ssdeep: 49152:PhbNVHUylYcWtO8w4JxsOvJRw5LtImArZZtySrpMl54zhReLKEe:PvVHUFe4/sm36ShrtVwaheKEe
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T180952302F7D34435F669057DD8A1C088AF3B797969F1142E2EFCD60E5ABD1816C3B9A0
sha3_384: f4ab8d98a664454630e876940b58f2f7b6a9b51b4b75297f70ad22b599480411534538c4eb3f8070df9b86dac6a0dea8
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2010-04-10 16:57:59

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Staforce Team
FileDescription: Активатор Office 2010
FileVersion: 2010
LegalCopyright: Staforce Team
ProductName: Активатор Office 2010
ProductVersion: 3.1
Translation: 0x0000 0x04b0

HackTool.Win32.KMSAuto.i also known as:

BkavW32.Common.D2137C58
LionicHacktool.Win32.KMSActivator.3!c
MicroWorld-eScanApplication.Hacktool.KMSActivator.BG
FireEyeApplication.Hacktool.KMSActivator.BG
CAT-QuickHealHackTool.KMSAuto.S71577
SkyhighBehavesLike.Win32.ObfuscatedPoly.tc
McAfeeArtemis!7A596F43E30C
Cylanceunsafe
SangforHacktool.Win32.KMSAuto.Vgoy
SymantecPUA.InstallCore
ESET-NOD32a variant of Win32/HackKMS.A potentially unsafe
TrendMicro-HouseCallTROJ_GEN.R002C0DBG24
KasperskyHackTool.Win32.KMSAuto.i
BitDefenderApplication.Hacktool.KMSActivator.BG
EmsisoftApplication.Hacktool.KMSActivator.BG (B)
DrWebTrojan.DownLoader26.23169
VIPREApplication.Hacktool.KMSActivator.BG
TrendMicroTROJ_GEN.R002C0DBG24
SophosKeygen (PUA)
WebrootW32.Malware.Gen
VaristW32/Risk.CPMH-7345
MAXmalware (ai score=100)
KingsoftWin32.HackTool.KMSAuto.i
MicrosoftTrojan:Win32/Phonzy.A!ml
XcitiumApplicUnwnt@#3pzsk6oead550
ArcabitApplication.Hacktool.KMSActivator.BG
ZoneAlarmHackTool.Win32.KMSAuto.i
GDataApplication.Hacktool.KMSActivator.BG
BitDefenderThetaGen:NN.ZexaF.36804.jmW@aKDmhmj
ALYacApplication.Hacktool.KMSActivator.BG
VBA32Trojan.Downloader
MalwarebytesGeneric.Malware/Suspicious
RisingTrojan.Generic@AI.90 (RDML:cSHVIstLPPfDywmuQDV2dA)
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.3405.susgen
FortinetW32/Backdoor!tr
DeepInstinctMALICIOUS

How to remove HackTool.Win32.KMSAuto.i?

HackTool.Win32.KMSAuto.i removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment