Malware

What is “Win32/Keygen.AOO potentially unsafe”?

Malware Removal

The Win32/Keygen.AOO potentially unsafe is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Keygen.AOO potentially unsafe virus can do?

  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Keygen.AOO potentially unsafe?


File Info:

crc32: FE8B22DD
md5: 9d372eda08d528ddfd36beb3ca70a8ac
name: 9D372EDA08D528DDFD36BEB3CA70A8AC.mlw
sha1: 074b6bfdad03ac3ea738dea6cd2a31d2d41dcb9a
sha256: d0947bf379defbe5160d71acface3d4ce363102904cd511c651b577ec308a15d
sha512: dc2581741a3ba81caacb7f3e00b4ee3e2ca8140d944c80ef8a1ee4ee6da27b9f630ec38710a2a3ec75d6434d956c5692a963e4aa81002df14bdffa4480328dcc
ssdeep: 24576:w2G/nvxW3WflbnyQNPGUABaYonrkk6+IeXMFaDRb89f0BbCam:wbA3AlryQNP/A/o7ZIlFaDa0l2
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Keygen.AOO potentially unsafe also known as:

BkavW32.AIDetect.malware2
K7AntiVirusUnwanted-Program ( 0056d3091 )
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Strictor.244488
CAT-QuickHealTrojan.Wacatac
ALYacGen:Variant.Strictor.244488
ZillyaTrojan.ScriptKD.JS.10
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderGen:Variant.Strictor.244488
K7GWUnwanted-Program ( 0056d3091 )
Cybereasonmalicious.a08d52
CyrenW32/Trojan.SVHA-0483
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Keygen.AOO potentially unsafe
APEXMalicious
AlibabaTrojan:Win32/Occamy.60df43f8
SophosGeneric ML PUA (PUA)
BitDefenderThetaAI:Packer.06AC77E319
TrendMicroTROJ_GEN.R002C0DLG20
McAfee-GW-EditionBehavesLike.Win32.Generic.th
FireEyeGeneric.mg.9d372eda08d528dd
EmsisoftGen:Variant.Strictor.244488 (B)
eGambitUnsafe.AI_Score_98%
MicrosoftProgram:Win32/Wacapew.C!ml
GridinsoftRansom.Win32.Wacatac.oa
ArcabitTrojan.Strictor.D3BB08
GDataGen:Variant.Strictor.244488
McAfeeArtemis!9D372EDA08D5
MAXmalware (ai score=81)
MalwarebytesRansom.Mamo
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0DLG20
RisingTrojan.Occamy!8.F1CD (CLOUD)
YandexTrojan.Igent.bVEEHm.26
IkarusTrojan-Ransom.GenericKD

How to remove Win32/Keygen.AOO potentially unsafe?

Win32/Keygen.AOO potentially unsafe removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment