AutoKMS.exe

AutoKMS

The application AutoKMS.exe has been detected as a potentially unwanted program by 38 anti-malware scanners.
Product:
AutoKMS

Version:
2.1.6.0

MD5:
102f77dc6d6f220656c7420297697d8c

SHA-1:
56c948b731301a99a913d97cf18bf5268a9fb014

SHA-256:
ba6b0d6bfbd87445d0eccb73fb1e1db5e02dcf4eb57e980e9f390796cda3631b

Scanner detections:
38 / 68

Status:
Potentially unwanted

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/25/2024 3:37:29 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Virtob.Gen.12
918

Agnitum Outpost
Trojan.Gendal
7.1.1

AhnLab V3 Security
Win32/Virut.F
2014.08.01

Avira AntiVirus
W32/Virut.Gen
7.11.30.172

avast!
Vitro
140617-1

AVG
Win32/Virut.AN
2014.0.3986

Bitdefender
Win32.Virtob.Gen.12
1.0.20.1060

Bkav FE
W32.QuintesLTK.Trojan
1.3.0.4613

Clam AntiVirus
Win.Trojan.Keygen-60
0.98/19168

Comodo Security
UnclassifiedMalware
17447

Dr.Web
Win32.Virut.56
9.0.1.05190

Emsisoft Anti-Malware
Win32.Virtob.Gen.12
8.14.07.31.03

ESET NOD32
MSIL/HackKMS
8.9176

Fortinet FortiGate
W32/FakeAV.RQ!tr
7/31/2014

F-Prot
W32/Heuristic-210!Eldorado (not disinfectable)
4.6.5.141

F-Secure
Win32.Virtob.Gen.12
11.2014-31-07_5

G Data
Win32.Virtob.Gen.12
14.7.24

IKARUS anti.virus
not-a-virus.Keygen.KMS
t3scan.2.2.29

K7 AntiVirus
Virus
13.182.12911

Kaspersky
Virus.Win32.Virut
15.0.0.494

Malwarebytes
Trojan.Agent.H
v2014.09.10.02

McAfee
Generic PUP.z!gp
5600.7052

Microsoft Security Essentials
1.163.1557.0

MicroWorld eScan
Win32.Virtob.Gen.12
15.0.0.636

NANO AntiVirus
Virus.Win32.Virut.hpeg
0.28.2.61148

Norman
Suspicious_Gen2.NOZBW
11.20140731

nProtect
Virus/W32.Virut.Gen
14.07.31.01

Panda Antivirus
W32/Sality.AO
14.07.31.03

Qihoo 360 Security
Virus.Win32.Virut.O
1.0.0.1015

Quick Heal
W32.Virut.G
7.14.14.00

Rising Antivirus
PE:Malware.MSIL.Injector!1.9C4B
23.00.65.14729

Sophos
Generic PUA FD
4.96

Total Defense
Win32/Virut.17408
37.0.11091

Trend Micro House Call
TROJ_SPNR.0BJS11
7.2.212

Trend Micro
TROJ_SPNR.0BJS11
10.465.31

Vba32 AntiVirus
Virus.Virut.14
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
24402

ViRobot
Win32.Virut.AM
2011.4.7.4223

File size:
744 KB (761,856 bytes)

Product version:
2.1.6.0

Copyright:
CODYQX4 & Bosh

Original file name:
AutoKMS.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\windows\autokms\autokms.exe

File PE Metadata
Compilation timestamp:
8/16/2009 1:27:50 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:LR2NdjhtebYR/FZo5JWOqC+W/oju9e6F9I1O9UJUQTFgNZUjQGp5hWpRQy6B5EvB:LRMUJFqSelJhWpR86XTkC8Mq5ZtYVNr

Entry address:
0x59A95

Entry point:
08, FD, 8D, 8A, 09, 0B, 48, 31, 10, E1, 00, D9, 68, 14, 6A, 00, 00, F8, 5A, F6, D5, EB, B6, 00, 00, 00, 84, 2D, CA, 19, 4D, 00, 00, D0, 32, 58, 16, 00, 05, 35, 58, C6, FD, 80, FC, 43, 1C, 2C, 90, E9, 7C, FF, FF, FF, 00, A9, 91, 1A, A4, ED, 00, 08, E8, 00, 9D, 59, F5, 78, 0B, 8C, 04, 44, 00, 0D, 7F, 58, 83, 00, 4A, 2A, E1, 7B, 00, 29, 00, 2D, 2F, 00, 07, 3F, 64, 73, 00, 6B, FD, 6B, 8D, E9, B6, FC, 43, 00, 85, DF, 50, F3, 83, 62, DD, 6B, 23, C8, DB, 44, 07, BD, 95, 6D, 70, 81, C5, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.8000

Code size:
351 KB (359,424 bytes)

Remove AutoKMS.exe - Powered by Reason Core Security