Crack

Win32/HackKMS.AV potentially unsafe removal instruction

Malware Removal

The Win32/HackKMS.AV potentially unsafe is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/HackKMS.AV potentially unsafe virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/HackKMS.AV potentially unsafe?


File Info:

crc32: 4F757698
md5: 2ac6e3a371d2f3fda5d54df70b928022
name: HEU_KMS_Activator_v11.1.0.exe
sha1: 84c2958686051947f4baaf2cca8cca9c2d382ffe
sha256: 3ab0a5add2b649a7b5e2903fc293227fcdf33df9d9f5874759da67e701b24aee
sha512: 0b75b61e0e80e8f6fe5f523754b57454cb91550339c5aa37eaf966e2e8d9976f9d5826fca9961c197a4930ca76e1042cb136be59a345d80cb519fa021afcfa9f
ssdeep: 98304:lssAdQ7j6bNTyeI8VMcrmEpuaE4385XQw+L+Qo3ncB:i1gjGI8ecKaE+WgT+QyncB
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright(C) 2012-2013 By Zbezj
CompanyName: HEU CNST
FileVersion: 11.1.0.0
Comments: x672cx5730KMSx6fc0x6d3bxff0cx65e0x9700x8054x7f51
FileDescription: HEU KMS Activator
Translation: 0x0804 0x04b0

Win32/HackKMS.AV potentially unsafe also known as:

MicroWorld-eScanTrojan.GenericKD.32417583
CAT-QuickHealHacktool.Autokms
McAfeeArtemis!2AC6E3A371D2
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabRiskware.Win32.HackKMS.1!c
SangforMalware
K7AntiVirusTrojan ( 700000111 )
BitDefenderTrojan.GenericKD.32417583
K7GWTrojan ( 700000111 )
Cybereasonmalicious.371d2f
ArcabitTrojan.Generic.D1EEA72F
Invinceaheuristic
CyrenW32/Trojan.IJBN-1595
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/HackKMS.AV potentially unsafe
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Autoit-6753917-0
Kasperskynot-a-virus:RiskTool.Win32.HackKMS.d
AlibabaRiskware:Win32/KMSAuto.73584feb
NANO-AntivirusRiskware.Win32.HackKMS.fnztqd
ViRobotTrojan.Win32.A.Agent.690283
Ad-AwareTrojan.GenericKD.32417583
EmsisoftTrojan.GenericKD.32417583 (B)
ComodoTrojWare.Win32.Hider.REXR@5364l6
ZillyaTool.KMSAuto.Win32.508
McAfee-GW-EditionBehavesLike.Win32.Agent.wc
FortinetW32/Generic_PUA_NL.Z
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.2ac6e3a371d2f3fd
SophosGeneric PUA NL (PUA)
F-ProtW32/Trojan2.NVGH
WebrootW32.Malware.Heur
eGambitUnsafe.AI_Score_97%
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.BTSGeneric
Endgamemalicious (high confidence)
MicrosoftHackTool:Win32/AutoKMS
ZoneAlarmnot-a-virus:RiskTool.Win32.HackKMS.d
AhnLab-V3Unwanted/Win32.KMSActivator.R202307
VBA32IMWorm.Sohanad
ALYacTrojan.GenericKD.32417583
MalwarebytesRiskWare.KMS
PandaTrj/CI.A
RisingTrojan.Win32.Malware.bmz (CLASSIC:bWQ1OkW5uAen2/GxhvLhSHSeu7k)
Ikarusnot-a-virus:Activator.KMS
MaxSecureTrojan.Malware.9671996.susgen
GDataWin32.Riskware.HackKMS.L
BitDefenderThetaGen:NN.ZexaF.34126.cqX@aWArSIj
AVGWin64:Malware-gen
AvastWin64:Malware-gen
CrowdStrikewin/malicious_confidence_80% (W)

How to remove Win32/HackKMS.AV potentially unsafe?

Win32/HackKMS.AV potentially unsafe removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment