Crack

HackTool:Win32/AutoKMS.E!MSR removal tips

Malware Removal

The HackTool:Win32/AutoKMS.E!MSR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What HackTool:Win32/AutoKMS.E!MSR virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A scripting utility was executed
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine HackTool:Win32/AutoKMS.E!MSR?


File Info:

crc32: A4C13D50
md5: cf973e3cc9f47b5b2e3305f8b17071eb
name: activar2010.exe
sha1: 5e844596f34b82e8a315b928c5195c73a74fc877
sha256: 424952ee44121a3e77b65a36d56e6e4e9db5c1c86e2f090b0647ba3c30d03d3c
sha512: 5580afd55669c28fc135f231afd0f07f99b996d77e615ce997a4d2a0611fd551ffa514173192f6aeb38d4488a73f3d332bb26309361e278060311203fe483ece
ssdeep: 49152:x1lXDyhWpnDhWpjMe0A7NC49ZDYSX1UFqQmNeLa1o3kYQHjOCAJ/Lsb63lqZGNm:xPD+DPN2UxAJDh3Fy
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: CODYQX4 & Bosh
Assembly Version: 1.0.0.0
InternalName: Office 2010 Toolkit.exe
FileVersion: 2.0.0.0
ProductName: Office 2010 Toolkit
ProductVersion: 2.0.0.0
FileDescription: Office 2010 Toolkit
OriginalFilename: Office 2010 Toolkit.exe

HackTool:Win32/AutoKMS.E!MSR also known as:

FireEyeGeneric.mg.cf973e3cc9f47b5b
CAT-QuickHealPUA.RiskwareFC.S8706804
VIPRETrojan.Win32.Generic!BT
AegisLabHacktool.MSIL.KMSAuto.3!c
SangforMalware
K7AntiVirusUnwanted-Program ( 004bb5561 )
K7GWUnwanted-Program ( 004bb5561 )
Cybereasonmalicious.6f34b8
TrendMicroHKTL_PATCHER
BitDefenderThetaGen:NN.ZemsilF.34090.@p0@aqrLFUm
CyrenW32/Keygen.GEDR-6099
SymantecPUA.Keygen.KMS
TrendMicro-HouseCallHKTL_PATCHER
GDataWin32.Riskware.HackKMS.AC
KasperskyHackTool.MSIL.KMSAuto.a
AlibabaHackTool:MSIL/KMSAuto.5d450e29
NANO-AntivirusTrojan.Win32.KMSAuto.eojawh
APEXMalicious
TencentMalware.Win32.Gencirc.10b45f7e
SophosKeygen (PUA)
ComodoMalware@#58lrqj2l9ug
ZillyaWorm.Allaple.Win32.29482
Invinceaheuristic
McAfee-GW-EditionGeneric HTool.j
SentinelOneDFI – Malicious PE
F-ProtW32/Keygen
JiangminTrojan.Generic.vafi
eGambitUnsafe.AI_Score_99%
MAXmalware (ai score=99)
Antiy-AVLTrojan[Packed]/Win32.Klone
Endgamemalicious (high confidence)
ZoneAlarmHackTool.MSIL.KMSAuto.a
MicrosoftHackTool:Win32/AutoKMS.E!MSR
AhnLab-V3Unwanted/Win32.Activator.R266837
McAfeeGeneric HTool.j
CylanceUnsafe
ZonerTrojan.Win32.48661
ESET-NOD32a variant of MSIL/HackKMS.A potentially unsafe
RisingMalware.Undefined!8.C (CLOUD)
YandexPUP.Agent!
IkarusHackTool.MSIL.KMSAuto
MaxSecureTrojan.Malware.3405.susgen
CrowdStrikewin/malicious_confidence_60% (W)

How to remove HackTool:Win32/AutoKMS.E!MSR?

HackTool:Win32/AutoKMS.E!MSR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment