Crack

MSIL/HackKMS.G potentially unsafe information

Malware Removal

The MSIL/HackKMS.G potentially unsafe is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/HackKMS.G potentially unsafe virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • Attempts to modify Internet Explorer’s start page
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs
  • Uses suspicious command line tools or Windows utilities

How to determine MSIL/HackKMS.G potentially unsafe?


File Info:

crc32: 2C8008FD
md5: 4bde8e3e0d3b84e553d0581e81f19af3
name: office_2010_toolkit_2.2.3.exe
sha1: 42b1d30478407edccdc5c402cc2f2ca98425cb33
sha256: 6332f5c60910bb93c958f0fb5b8472bb032e685c42827f278e0a70d501de344a
sha512: 403007b3bc86857a629863052e092177278f929f5dc70fa4c25c74fd1ecd9e728257c91c714ea1a247ffcb58b48db7430b3432b6b81c400683b4b30021782cf6
ssdeep: 393216:5oAdlYDr0zCfkNymzAjkqDsm7Q57257twlyti1XZKhY:5oAdL1xqpc57/YuXZKhY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

MSIL/HackKMS.G potentially unsafe also known as:

MicroWorld-eScanTrojan.GenericKD.31161809
FireEyeTrojan.GenericKD.31161809
CAT-QuickHealTrojan.IGENERIC
McAfeeArtemis!4BDE8E3E0D3B
AegisLabHacktool.Win32.KMSAuto.3!c
BitDefenderTrojan.GenericKD.31161809
K7GWUnwanted-Program ( 004bb5561 )
K7AntiVirusUnwanted-Program ( 004bb5561 )
TrendMicroCRCK_PATCH
SymantecW32.Spybot.Worm
AvastWin32:Malware-gen
GDataMSIL.Riskware.HackKMS.H
KasperskyHackTool.Win32.KMSAuto.i
AlibabaHackTool:Win32/KMSAuto.9a9cc541
NANO-AntivirusTrojan.Win32.KMSAuto.esuqnc
RisingTrojan.Generic@ML.80 (RDML:SdiHfxYtP+qh6Gmltq6Rtg)
Ad-AwareTrojan.GenericKD.31161809
SophosKeygen (PUA)
ComodoMalware@#2mysn3175b5sx
F-SecureTrojan.TR/StartPage.khogb
DrWebTool.KMS.6
McAfee-GW-EditionCrack-Generic
EmsisoftTrojan.GenericKD.31161809 (B)
CyrenW32/Trojan.MSGR-7235
WebrootW32.HackTool.Gen
AviraTR/StartPage.khogb
ArcabitTrojan.Generic.D1DB7DD1
ZoneAlarmHackTool.Win32.KMSAuto.i
MicrosoftHackTool:Win32/Keygen
ALYacTrojan.GenericKD.31161809
MAXmalware (ai score=100)
CylanceUnsafe
PandaTrj/CI.A
ZonerTrojan.Win32.72772
ESET-NOD32a variant of MSIL/HackKMS.G potentially unsafe
TrendMicro-HouseCallCRCK_PATCH
TencentWin32.Hacktool.Kmsauto.Pgxi
YandexPUP.Agent!
IkarusHackTool.MSIL.KMSAuto
FortinetAdware/HackKMS
MaxSecureTrojan.Malware.9913398.susgen
AVGWin32:Malware-gen
Cybereasonmalicious.e0d3b8
Paloaltogeneric.ml

How to remove MSIL/HackKMS.G potentially unsafe?

MSIL/HackKMS.G potentially unsafe removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment