Categories: Crack

Win32/HackTool.WinActivator.AV potentially unsafe information

The Win32/HackTool.WinActivator.AV potentially unsafe is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/HackTool.WinActivator.AV potentially unsafe virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • A script or command line contains a long continuous string indicative of obfuscation
  • Anomalous binary characteristics

How to determine Win32/HackTool.WinActivator.AV potentially unsafe?


File Info:

name: D17A3D012A0A27A814F5.mlwpath: /opt/CAPEv2/storage/binaries/5ba6e8dec75199c18e32c694e39dd36f18ec73572776a64b777c5d1f884872edcrc32: C8A1C219md5: d17a3d012a0a27a814f5db046f346229sha1: d41121cd90c29f6bad75c9cffa61e997cd5c54ecsha256: 5ba6e8dec75199c18e32c694e39dd36f18ec73572776a64b777c5d1f884872edsha512: efc6793db349698d17ab93677271f57ace0808111af32a9afd9005880f2ea9d734215a71eefb4b4387e6fd5ea5f8c7f8278797289a1611c61dec2c3ee0f2b24cssdeep: 196608:Ij2EpMTXSlsPwLV6dp7RUYuyu8KP1KP8:IUmfKRnuyu8ojtype: PE32 executable (GUI) Intel 80386, for MS Windowstlsh: T1138623226FFD9360CE665032FE6567406E7B6C611130F84B2EC43E79AA73163066F693sha3_384: 99355de8d302cf574fd1fa413f2271064e834a53af5f8c08345376da559ca23f8220ca9ef1fc715fbc7bdc4e95273d73ep_bytes: e8b8d00000e97ffeffffcccccccccccctimestamp: 2021-07-13 15:42:53

Version Info:

FileVersion: 24.0.0.0Comments: KMS/数字权利/KMS38/OEM激活FileDescription: HEU KMS Activator™ProductVersion: 3.3.14.2LegalCopyright: ©2012-2021 www.heu8.com & 知彼而知己Productname: HEU KMS ActivatorCompanyName: 知彼而知己OriginalFilename: HEU_KMS_Activator_v24.0.0InternalName: HEU_KMS_Activator_v24.0.0Translation: 0x0804 0x04b0

Win32/HackTool.WinActivator.AV potentially unsafe also known as:

Bkav W32.AIDetect.malware1
Lionic Trojan.Win32.Generic.4!e
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.50053014
FireEye Trojan.GenericKD.50053014
CAT-QuickHeal PUA.KMS.S24702025
ALYac Trojan.GenericKD.50053014
Cylance Unsafe
Sangfor Hacktool.Win32.KMSAuto.gen
K7AntiVirus Trojan ( 700000111 )
K7GW Trojan ( 700000111 )
CrowdStrike win/grayware_confidence_100% (W)
Cyren W32/Application.YRJO-3887
Symantec Trojan.Gen.2
ESET-NOD32 Win32/HackTool.WinActivator.AV potentially unsafe
TrendMicro-HouseCall TROJ_GEN.R002C0WD522
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky HEUR:HackTool.Win32.KMSAuto.gen
BitDefender Trojan.GenericKD.50053014
Avast Win32:Malware-gen
Tencent Pua:Hacktool.Win32.Kmsauto.16000261
Ad-Aware Trojan.GenericKD.50053014
Sophos Generic PUA NE (PUA)
DrWeb Trojan.MulDrop17.64444
TrendMicro TROJ_GEN.R002C0WD522
McAfee-GW-Edition BehavesLike.Win32.TrojanAitInject.wc
Emsisoft Trojan.GenericKD.50053014 (B)
APEX Malicious
GData Trojan.GenericKD.50053014
Arcabit Trojan.Generic.D2FBBF96
Microsoft Backdoor:Win32/Bladabindi!ml
AhnLab-V3 Trojan/AU3.AutoInj.S1107
McAfee Artemis!D17A3D012A0A
MAX malware (ai score=85)
VBA32 Trojan.Autoit.Banker
Malwarebytes RiskWare.KMS
MaxSecure Trojan.Malware.121218.susgen
Fortinet Riskware/WinActivator
AVG Win32:Malware-gen
Panda Trj/Genetic.gen

How to remove Win32/HackTool.WinActivator.AV potentially unsafe?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

UDS:WebToolbar.NSIS.BigSeek information

The UDS:WebToolbar.NSIS.BigSeek is considered dangerous by lots of security experts. When this infection is active,…

4 mins ago

Malware.AI.3927748087 (file analysis)

The Malware.AI.3927748087 is considered dangerous by lots of security experts. When this infection is active,…

15 mins ago

What is “Zusy.431152”?

The Zusy.431152 is considered dangerous by lots of security experts. When this infection is active,…

25 mins ago

About “Jalapeno.1959” infection

The Jalapeno.1959 is considered dangerous by lots of security experts. When this infection is active,…

35 mins ago

Worm.Win32.Vobfus.dgii removal guide

The Worm.Win32.Vobfus.dgii is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Trojan.Win32.Hesv.bxdc information

The Trojan.Win32.Hesv.bxdc is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago