kmsauto net 2014 1 2 4 aktivator windows 8.exe

LLC ITC

The application kmsauto net 2014 1 2 4 aktivator windows 8.exe by LLC ITC has been detected as adware by 28 anti-malware scanners.
Publisher:
LLC ITC  (signed and verified)

MD5:
b603d639da1ae945a0714a88a93abdf8

SHA-1:
56bd1a3655e3b64c69f403241c9a7470a750a268

SHA-256:
f27e4640e7d0282eb3cb84f6b859c1c3718224329f656a48003f4545462ae69b

Scanner detections:
28 / 68

Status:
Adware

Analysis date:
4/26/2024 8:33:39 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Symmi.45421
6209727

AhnLab V3 Security
Adware/Win32.LoadMoney
2014.12.21

Avira AntiVirus
Adware/Webalta.qoys
7.11.196.252

avast!
Win32:Webalta-M [PUP]
141214-1

AVG
Win32/Cryptor
2014.0.4235

Bitdefender
Gen:Variant.Adware.Symmi.45421
1.0.20.1775

Dr.Web
Trojan.LoadMoney.272
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Adware.Symmi.45421
9.0.0.4668

ESET NOD32
Win32/AdWare.LoadMoney.NW application
7.0.302.0

Fortinet FortiGate
Riskware/LMN
12/21/2014

F-Prot
W32/A-7efcca86
v6.4.7.1.166

F-Secure
Gen:Variant.Adware.Symmi.45421
5.13.68

G Data
Gen:Variant.Adware.Symmi.45421
14.12.24

IKARUS anti.virus
PUA.LoadMoney
t3scan.1.8.5.0

K7 AntiVirus
Trojan
13.188.14395

Kaspersky
not-a-virus:Downloader.Win32.LMN
15.0.0.543

McAfee
Program.Packed-CQ
16.8.708.2

Microsoft Security Essentials
Threat.Undefined
1.191.519.0

MicroWorld eScan
Gen:Variant.Adware.Symmi.45421
15.0.0.1065

NANO AntiVirus
Trojan.Win32.LMN.dcjfnf
0.28.6.64267

Norman
Gen:Variant.Adware.Symmi.45421
04.12.2014 14:30:06

Panda Antivirus
Trj/Genetic.gen
14.12.21.05

Qihoo 360 Security
Malware.QVM20.Gen
1.0.0.1015

Reason Heuristics
PUP.ITC.k
14.12.22.11

Rising Antivirus
PE:Malware.XPACK-HIE/Heur!1.9C48
23.00.65.141219

Sophos
Virus 'Troj/LdMon-G'
5.09

Vba32 AntiVirus
Malware-Cryptor.Limpopo
3.12.26.3

VIPRE Antivirus
Threat.4657539
35418

File size:
453.3 KB (464,184 bytes)

File type:
Executable application (Win32 EXE)

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
6/26/2014 3:00:00 AM

Valid to:
6/27/2015 2:59:59 AM

Subject:
CN=LLC ITC, O=LLC ITC, STREET=Vvedenskogo 11/3, L=Moscow, S=Moscow oblast, PostalCode=117342, C=RU

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00F4DBD55156EE0DAFED4BAB130328504E

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:QlRJpj0/G2O1807lcKQ2E3O4xxewAuaBJt96Ca:Qlvpv2OKAl82ENeA

Entry address:
0x1000

Entry point:
E9, AF, 2B, 06, 00, 89, 15, FC, 50, 46, 00, 89, 0D, AA, 50, 46, 00, C7, 05, 46, 50, 46, 00, 24, 38, 01, 00, BA, 87, 00, 00, 00, 89, 7C, 24, D8, C3, 8D, 40, 00, C3, 8D, 40, 00, FF, 25, 24, 50, 46, 00, B8, 28, 10, 40, 00, C3, 55, 8B, EC, 83, C4, E8, C6, 45, FF, 00, FE, 05, DE, 50, 46, 00, C7, 05, BA, 50, 46, 00, 05, 0D, 01, 00, 87, 05, F7, 50, 46, 00, A1, F4, 75, 46, 00, 8B, 15, 20, 80, 46, 00, 8B, 04, 90, 3B, 45, 08, 73, 04, C6, 45, FF, 01, 89, 15, 48, 50, 46, 00, 8B, 1D, 9E, 50, 46, 00, C7, 05, F2, 50, 46...
 
[+]

Packer / compiler:
Xtreme-Protector v1.05

Code size:
396.5 KB (406,016 bytes)