Crack

What is “HackTool:Win32/AutoKMS!pz”?

Malware Removal

The HackTool:Win32/AutoKMS!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What HackTool:Win32/AutoKMS!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine HackTool:Win32/AutoKMS!pz?


File Info:

name: A70CA578D2CDEF019D28.mlw
path: /opt/CAPEv2/storage/binaries/d5355576a2910aef9be755d53d2898e606ed8a73112b8380ece29cc7fa766f99
crc32: 9262AB50
md5: a70ca578d2cdef019d284de84521004e
sha1: 4efe81c94e070a7683f014bab7927b752120598e
sha256: d5355576a2910aef9be755d53d2898e606ed8a73112b8380ece29cc7fa766f99
sha512: de2e1d7425f612ca2a582ebabe7e7feca8e0ed3b11290e1bf2a44cda2b9b646b34493aa2b29fb55fc6343e565dc87fea6b53070c9ba4481f5a5d92673bf08dec
ssdeep: 3072:rUmR/pGtBKYYA/T2PT0AC3r1sXldpkRvvV2juQyJzD+2l+Wz6qhavBFzcSKZLXgH:rJ/pGPKmO8mDmXHR+WX8Bacx9
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T13B549E117B918076D9B3027649FC9732147DFD620B61AACBE3D8CE9DAB344C26B31B52
sha3_384: 78114844a55de01acf6bfd84741b9ad890213c001578ef8927ed2bc3dd2e5ba431529adabe096cc1c07fb6d43b3e6d85
ep_bytes: e8e2590000e97bfeffff558becff155c
timestamp: 2013-02-13 23:29:37

Version Info:

0: [No Data]

HackTool:Win32/AutoKMS!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Midie.106179
CAT-QuickHealTrojan.MauvaiseRI.S5244032
SkyhighBehavesLike.Win32.Generic.dh
McAfeePUP-XDB-PT
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
CrowdStrikewin/grayware_confidence_100% (D)
BaiduWin32.Trojan.Generic.i
VirITTrojan.Win32.Genus.PRF
SymantecSMG.Heur!gen
ESET-NOD32a variant of Win32/HackTool.KMSAuto.A potentially unsafe
APEXMalicious
TrendMicro-HouseCallHackTool.Win32.AutoKMS.SMFRED1
ClamAVWin.Tool.Kmsactivator-9780682-0
KasperskyHEUR:HackTool.Win32.KMSAuto.gen
BitDefenderGen:Variant.Midie.106179
NANO-AntivirusTrojan.Win32.KMSAuto.icdofu
EmsisoftGen:Variant.Midie.106179 (B)
GoogleDetected
DrWebTool.KMS.11
VIPREGen:Variant.Midie.106179
TrendMicroHackTool.Win32.AutoKMS.SMFRED1
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.a70ca578d2cdef01
SophosKMS Activator (PUA)
SentinelOneStatic AI – Malicious PE
JiangminHackTool.KMSAuto.ne
VaristW32/S-1cc9666a!Eldorado
MAXmalware (ai score=83)
Antiy-AVLHackTool/Win32.KMSAuto.a
Kingsoftmalware.kb.a.969
MicrosoftHackTool:Win32/AutoKMS!pz
XcitiumApplication.Win32.HackKMS.DS@5nuvyt
ArcabitTrojan.Midie.D19EC3
ZoneAlarmHEUR:HackTool.Win32.KMSAuto.gen
GDataWin32.Riskware.HackKMS.Y
CynetMalicious (score: 100)
AhnLab-V3HackTool/Win32.AutoKMS.R178729
Acronissuspicious
ALYacGen:Variant.Midie.106179
Cylanceunsafe
PandaTrj/Genetic.gen
RisingHack.Win32.Application.a (CLASSIC)
YandexTrojan.GenAsa!LwRuShYVu8s
IkarusPUA.HackTool
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/HacktoolKms.9A19!tr
BitDefenderThetaGen:NN.ZexaF.36802.ryX@a4lfDpgi
Cybereasonmalicious.8d2cde
DeepInstinctMALICIOUS
alibabacloudTrojan.Win32.AutoKMS.6e4ab6fe

How to remove HackTool:Win32/AutoKMS!pz?

HackTool:Win32/AutoKMS!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment