kms.exe

OPEN.co., ltd

The application kms.exe by OPEN.co., ltd has been detected as adware by 18 anti-malware scanners. According to AVG, this software downloads additional adware offers during setup.
Publisher:
OPEN.s.  (signed by OPEN.co., ltd)

Version:
0.1.1.550

MD5:
a5203bcbf9652b03646f3d949a82bb4d

SHA-1:
34f0b7730894a5dd0afadd495caa6347db2a0b1c

Scanner detections:
18 / 68

Status:
Adware

Analysis date:
4/25/2024 2:50:01 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Packed/PECompact
7.1.1

AhnLab V3 Security
PUP/Win32.Helper
15.01.31

Avira AntiVirus
TR/Delf.oiu.11
7.11.138.142

avast!
Win32:Adware-AZE [Adw]
2014.9-150131

AVG
Downloader
2016.0.3212

Baidu Antivirus
Trojan.Win32.Delf
4.0.3.15131

Bkav FE
W32.Clodee7.Trojan
1.3.0.4959

Comodo Security
UnclassifiedMalware
17982

Dr.Web
Adware.Searcher.1334
9.0.1.031

ESET NOD32
Win32/Delf.OIU (variant)
9.9582

IKARUS anti.virus
Win32.Downloader.TXB
t3scan.2.2.29

Malwarebytes
Adware.Kraddare
v2015.01.31.03

McAfee
Artemis!A5203BCBF965
5600.6868

Qihoo 360 Security
Win32/Trojan.Adware.37e
1.0.0.1015

Reason Heuristics
PUP.OPENco
15.1.31.15

Trend Micro House Call
TROJ_GEN.R0CBC0OHT13
7.2.31

Trend Micro
TROJ_GEN.R0CBC0OHT13
10.465.31

VIPRE Antivirus
Trojan.Win32.Generic
27690

File size:
326 KB (333,808 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Common path:
C:\Documents and Settings\{user}\Local settings\temp\kms.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
12/9/2011 9:00:00 AM

Valid to:
1/8/2013 8:59:59 AM

Subject:
CN="OPEN.co., ltd", O="OPEN.co., ltd", L="Gangnam-gu,", S=Seoul, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
5106D7E3FBF1E6CEC1B36F2B94378E7C

File PE Metadata
Compilation timestamp:
4/3/2012 5:55:07 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
6144:TX8gExQR0uF/f0uKd8/gLBGhgWap1gWQ6FGFY17OhoDveXDE:TX8UFn0D8/gLKSp1ZQ6HOhoK

Entry address:
0x1000

Entry point:
B8, 14, D9, 4F, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, E1, E6, 65, C1, 3A, F6, 83, 47, F1, 13, 84, EB, 86, D5, 2F, 56, 4B, C6, E0, C1, 93, 86, 0C, 7A, B9, CD, 12, 7E, 1E, 5C, 69, 36, CD, 57, 78, 0C, F0, C8, 02, 95, 42, 12, 2E, A8, AB, E0, B3, AA, DF, DD, DC, 5C, 4D, A5, 01, 09, B8, F7, 93, 62, 45, 7D, D3, B3, 39, 4A, 7E, CC, 5B, 5B, D5, 98, 13, 76, 8E, 32, 15, 18, E8, 6B, 4B, 62, D0, CF, C5, 16, 6A, 8B, 91, 54, EE, 70, CC...
 
[+]

Entropy:
7.9631

Packer / compiler:
PECompact v2

Code size:
647 KB (662,528 bytes)

Remove kms.exe - Powered by Reason Core Security