Risk

RiskWare.AutoKMS removal

Malware Removal

The RiskWare.AutoKMS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What RiskWare.AutoKMS virus can do?

  • Reads data out of its own binary image
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine RiskWare.AutoKMS?


File Info:

crc32: 32066DAA
md5: af184a1c59eabeea981562d4364bc78f
name: AF184A1C59EABEEA981562D4364BC78F.mlw
sha1: c05869cf902492e986545d008889d51b5a608772
sha256: 0042fa6d7a9b711fa8f25c7275e1b2708cfd17f53e74bb98cd854bd973338e2b
sha512: 40f4267a8211a5316c4858674c993fd25485f8eb3034eec2adde0b31fa424753e86e546b63b096ce2d53f5627e55edce0660da57476d838c0a3e71e2b68fadc4
ssdeep: 12288:WhkDgouVA2nxKkorvdRgQriDwOIxmxiZnYQE7PJcE4aEd1FMnP2lfFBDkTtxjS:GRmJkcoQricOIQxiZY1iaEdMP2lfFBiS
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
FileVersion: 3, 3, 8, 1
FileDescription:
Translation: 0x0809 0x04b0

RiskWare.AutoKMS also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 700000111 )
LionicTrojan.Win32.Zbot.mB61
Elasticmalicious (high confidence)
DrWebTrojan.Siggen6.23123
CynetMalicious (score: 100)
ALYacTrojan.Generic.23089389
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.165728
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojanSpy:Win32/AutInject.3e3b5806
K7GWTrojan ( 700000111 )
Cybereasonmalicious.c59eab
BaiduAutoIt.Trojan.Injector.bm
CyrenW32/AutoIt.AQ2.gen!Eldorado
SymantecSMG.Heur!gen
ESET-NOD32a variant of Win32/Injector.Autoit.AYX
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Zbot-7107265-0
BitDefenderTrojan.Generic.23089389
NANO-AntivirusTrojan.Script.Autoit.drhvzf
MicroWorld-eScanTrojan.Generic.23089389
TencentWin32.Trojan-spy.Zbot.Lnoa
Ad-AwareTrojan.Generic.23089389
ComodoTrojWare.Win32.Injector.EUXI@4yxp37
VIPRETrojan.Win32.Generic!BT
FireEyeGeneric.mg.af184a1c59eabeea
EmsisoftTrojan.Generic.23089389 (B)
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_51%
MicrosoftTrojan:Win32/AutInject
ArcabitTrojan.Generic.D16050ED
GDataTrojan.Generic.23089389
TACHYONTrojan-Spy/W32.ZBot.888868
AhnLab-V3Trojan/Win32.ZBot.C522796
McAfeeGenericATG-FAIE!AF184A1C59EA
MAXmalware (ai score=100)
VBA32Trojan.Autoit.F
MalwarebytesRiskWare.AutoKMS
PandaTrj/CI.A
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Autoit.AZA
FortinetW32/Zbot.OQWF!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove RiskWare.AutoKMS?

RiskWare.AutoKMS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment