Trojan

How to remove “Trojan:Win32/AutoKMS”?

Malware Removal

The Trojan:Win32/AutoKMS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/AutoKMS virus can do?

  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan:Win32/AutoKMS?


File Info:

crc32: 9A1482AD
md5: fee3764a3e9e5b5875e16fc12eac6f61
name: 28beb7a4954614aca64f89ec6374c1ee10794a3472bacde06d.exe
sha1: 5db62ee4a8790c579148094d15fbb890a9834537
sha256: a56056e816e9c5f7ebbef6df7cef9062cbacc57b83083b5670f5bbffc01d08ab
sha512: 15ffa6399436bd556ecc50a57842bcd72cb3a5723c25f67d7bff7ba5b455104b746c3f3260b9fd7cd89cbcb54a7dba2c6cca181dc82d9d841a3fc43d56a00dc0
ssdeep: 98304:KT925TGjjX8hP71mlZLQIHHDghhmLwGHFLWWuLLdKYowpHSPR+0gYp6FMdmrr:KUTIjCjoRLjghEwCWX3dFyPRvFd4r
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/AutoKMS also known as:

BkavHW32.Packed.
MicroWorld-eScanGen:Variant.Razy.551042
FireEyeGeneric.mg.fee3764a3e9e5b58
Qihoo-360HEUR/QVM19.1.EF8F.Malware.Gen
McAfeeArtemis!FEE3764A3E9E
ALYacGen:Variant.Razy.551042
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0054bb0d1 )
BitDefenderGen:Variant.Razy.551042
K7GWTrojan ( 0054bb0d1 )
Cybereasonmalicious.a3e9e5
TrendMicroPAK_Xed-3
BitDefenderThetaGen:NN.ZexaF.34084.@JW@aavVWjji
TrendMicro-HouseCallPAK_Xed-3
AvastWin32:Trojan-gen
GDataGen:Variant.Razy.551042
KasperskyHEUR:Trojan.Win32.Generic
AlibabaPacked:Win32/VMProtect.0320efb0
NANO-AntivirusVirus.Win32.Gen.ccmw
AegisLabTrojan.Win32.Midie.4!c
RisingTrojan.Crypto!8.364 (CLOUD)
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Razy.551042 (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen
ZillyaTrojan.Packed.Win32.167296
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SentinelOneDFI – Malicious PE
Trapminemalicious.high.ml.score
SophosMal/Generic-S
APEXMalicious
WebrootW32.Malware.Gen
AviraTR/Crypt.ZPACK.Gen
ArcabitTrojan.Razy.D86882
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/AutoKMS
AhnLab-V3Unwanted/Win32.RL_HackTool.R285325
Acronissuspicious
MAXmalware (ai score=99)
Ad-AwareGen:Variant.Razy.551042
MalwarebytesTrojan.MalPack.PES.Generic
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Packed.VMProtect.HR
TencentWin32.Hacktool.Inject.Eivb
YandexTrojan.VMProtect!
IkarusTrojan.Win32.VMProtect
eGambitUnsafe.AI_Score_92%
FortinetRiskware/VMProtectPacked
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan:Win32/AutoKMS?

Trojan:Win32/AutoKMS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment