Crack

HackTool:Win32/AutoKMS removal guide

Malware Removal

The HackTool:Win32/AutoKMS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What HackTool:Win32/AutoKMS virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Created a service that was not started

How to determine HackTool:Win32/AutoKMS?


File Info:

crc32: EF40E6D9
md5: a89c072c83a54cb5aa2c570f3d910a56
name: KMSpico_setup.exe
sha1: 3e14b4d93e9b4951982471624c6515627494feca
sha256: 2cfb9406ac9553c350a333f573a56226419f74747d7a6bdde24cbd81b1d7be4a
sha512: 1c2ce6381a7cd8361055d9eafa6a3f2c7a962a65434942be9d3384086b73af7ede8216607b6264b41dc8d4e0ec5543f220bdf7512adfa79f82b82a2877615b7e
ssdeep: 98304:BlvQ8xTsJI7zc6SNn1z5p8XGMpnVb0zhNNuzWl:HHxhczWXltVb0z3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: ByELDI
FileVersion: 10.1.7
CompanyName:
Comments: This installation was built with Inno Setup.
ProductName: KMSpico
ProductVersion: 10.1.7
FileDescription: KMSpico Setup
Translation: 0x0000 0x04b0

HackTool:Win32/AutoKMS also known as:

BkavW32.HfsAdware.216A
MicroWorld-eScanTrojan.GenericKD.30874325
CAT-QuickHealPUA.AutokmsFC.S6051031
McAfeeCrack-KMS
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusUnwanted-Program ( 004d38111 )
BitDefenderTrojan.GenericKD.30874325
TrendMicroPUA.Win32.AutoKMS.AD
CyrenW32/S-eb8730b5!Eldorado
SymantecPUA.Keygen.KMS!g3
ESET-NOD32a variant of MSIL/HackTool.IdleKMS.E potentially unsafe
AvastFileRepMetagen [PUP]
ClamAVWin.Trojan.Agent-5776536-0
Kasperskynot-a-virus:NetTool.Win64.RPCHook.a
AlibabaHackTool:Win32/AutoKMS.3c18b095
NANO-AntivirusRiskware.Win32.ProcPatcher.eilohf
Ad-AwareTrojan.GenericKD.30874325
EmsisoftApplication.HackTool (A)
ComodoMalware@#294x8136c1pji
DrWebTrojan.Moneyinst.709
Invinceaheuristic
McAfee-GW-EditionCrack-KMS
FireEyeTrojan.GenericKD.30874325
SophosKMS Activator (PUA)
IkarusHackTool.Win32.AutoKMS
F-ProtW32/S-eb8730b5!Eldorado
JiangminHackTool.MSIL.dgy
WebrootW32.Hacktool.Gen
FortinetRiskware/IdleKMS
Antiy-AVLHackTool/Win32.AutoKMS
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1D71AD5
ZoneAlarmnot-a-virus:NetTool.Win64.RPCHook.a
MicrosoftHackTool:Win32/AutoKMS
AhnLab-V3HackTool/Win32.Crack.C509549
VBA32Trojan.Moneyinst
ALYacTrojan.GenericKD.30874325
MAXmalware (ai score=100)
TrendMicro-HouseCallPUA.Win32.AutoKMS.AD
YandexRiskware.NetTool!
eGambitUnsafe.AI_Score_97%
GDataBAT.Application.Agent.VJNLGI
BitDefenderThetaGen:NN.ZemsilF.34084.Tm1@a8vJERd
AVGFileRepMetagen [PUP]
Cybereasonmalicious.c83a54
Paloaltogeneric.ml

How to remove HackTool:Win32/AutoKMS?

HackTool:Win32/AutoKMS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment