Risk

What is “RiskWare.KMS”?

Malware Removal

The RiskWare.KMS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What RiskWare.KMS virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine RiskWare.KMS?


File Info:

crc32: F44EA548
md5: 3e4e6091833b5b343142199f591d9fc2
name: HEU_KMS_Activator_v19.6.0.exe
sha1: c8da3112aec96c69874b08a34e9adb7245babde3
sha256: 99f37be737f2a1d0cfe958cc65fde94c310689d59304845c6e9a882bb75c08a7
sha512: 0f8c4c1aa612c0fc00c3383017a41b013f7ab483a685c1d2c0ad48d28da7274c5532915d6a7c34dc7a22fcde26aa4825d8dae5c0e010e29d99362858a172926c
ssdeep: 98304:f8sjkLiaEUfyTaD4Wu+29lZMea7B0zmFldv+QHI4/Lulf2UU:RjzaEUfX45+eR8HZl3LUU
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa92012-2019 www.heu8.com & x77e5x5f7cx800cx77e5x5df1
InternalName: HEU_KMS_Activator_v19.6.0
FileVersion: 19.6.0.0
CompanyName: x77e5x5f7cx800cx77e5x5df1
Comments: x672cx5730KMSx6fc0x6d3b/Win10x6570x5b57x6743x5229x6fc0x6d3b/KMS38x6fc0x6d3b
Productname: HEU KMS Activator
ProductVersion: 19.6.0.0
FileDescription: HEU KMS Activatorx2122
OriginalFilename: HEU_KMS_Activator_v19.6.0
Translation: 0x0804 0x04b0

RiskWare.KMS also known as:

DrWebTrojan.StartPage1.22693
MicroWorld-eScanGen:Variant.Strictor.218482
FireEyeGen:Variant.Strictor.218482
CAT-QuickHealTrojan.HacktoolWin32Autokms
McAfeeArtemis!3E4E6091833B
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 700000111 )
BitDefenderGen:Variant.Strictor.218482
K7GWTrojan ( 700000111 )
CrowdStrikewin/malicious_confidence_70% (W)
BitDefenderThetaGen:NN.ZexaE.34100.cqW@amh5jdd
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
GDataGen:Variant.Strictor.218482
KasperskyHackTool.Win32.HackKMS.m
AlibabaHackTool:Win32/HackKMS.a0bf88db
NANO-AntivirusTrojan.Win32.HackKMS.geintq
AegisLabTrojan.Win32.Generic.4!e
TencentWin32.Hacktool.Hackkms.Llrq
Endgamemalicious (high confidence)
SophosGeneric PUA MI (PUA)
ComodoMalware@#3w1bgv342jh0
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.tc
EmsisoftGen:Variant.Strictor.218482 (B)
IkarusPUA.HackKMS
CyrenW32/Trojan.JNIV-7679
WebrootW32.Trojan.Gen
ArcabitTrojan.Strictor.D35572
ZoneAlarmHackTool.Win32.HackKMS.m
MicrosoftHackTool:Win32/AutoKMS
AhnLab-V3HackTool/Win32.AutoKMS.C3501244
Acronissuspicious
ALYacGen:Variant.Strictor.218482
MAXmalware (ai score=88)
VBA32Trojan.StartPage
MalwarebytesRiskWare.KMS
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/RiskWare.HackTool.WinActivator.B
RisingPUA.Presenoker!8.F608 (CLOUD)
FortinetW32/Generic_PUA_EJ.BA
Ad-AwareGen:Variant.Strictor.218482
AVGWin32:Malware-gen
Paloaltogeneric.ml
MaxSecureTrojan.Malware.74581811.susgen

How to remove RiskWare.KMS?

RiskWare.KMS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment