kmsauto.exe

WZT

The application kmsauto.exe by WZT has been detected as a potentially unwanted program by 8 anti-malware scanners. This is a setup program which is used to install the application. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs. The file has been seen being downloaded from serv5.dailyuploads.net.
Publisher:
WZT  (signed and verified)

MD5:
2efa55fedc35ff4d202d940e75b61fce

SHA-1:
fa8bafb6132f269bc8297e431baf780344bd8876

SHA-256:
2ae4029e90a5def04c02ef12d8a4673ed46588ec0ddd95751f39ba6b9d5a07ad

Scanner detections:
8 / 68

Status:
Potentially unwanted

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
12/26/2024 6:20:03 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Unwanted/Win32.KMS
2015.11.20

Avira AntiVirus
SPR/HackKms.B
8.3.2.4

ESET NOD32
Win32/HackKMS.Q potentially unsafe (variant)
9.12597

IKARUS anti.virus
PUA.Hacktool.HackKMS
t3scan.1.9.5.0

K7 AntiVirus
Unwanted-Program
13.212.17918

McAfee
Artemis!2EFA55FEDC35
5600.6575

Reason Heuristics
PUP.MSFree.WZT.Meta (M)
16.2.27.17

Zillya! Antivirus
Adware.OutBrowse.Win32.62861
2.0.0.2520

File size:
6.3 MB (6,625,400 bytes)

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\programs\kmsauto.exe

Digital Signature
Signed by:

Authority:
WZT

Valid from:
11/8/2015 9:15:49 AM

Valid to:
1/1/2040 12:59:59 AM

Subject:
CN=WZT

Issuer:
CN=WZT

Serial number:
08A8E826950F1A9940262589FCAF0B8F

File PE Metadata
Compilation timestamp:
11/12/2015 3:26:09 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.50

CTPH (ssdeep):
196608:5MXyw9Oqyw7iywnvywwywHywWywbywmIiywa3ywuywQyw5:5rw9Onw7fwawtwSwLwewhwbwjwNw5

Entry address:
0x1000

Entry point:
68, 38, 09, 00, 00, 68, 00, 00, 00, 00, 68, 98, 74, A4, 00, E8, D6, B1, 01, 00, 83, C4, 0C, 68, 00, 00, 00, 00, E8, CF, B1, 01, 00, A3, 9C, 74, A4, 00, 68, 00, 00, 00, 00, 68, 00, 10, 00, 00, 68, 00, 00, 00, 00, E8, BC, B1, 01, 00, A3, 98, 74, A4, 00, B8, 27, 72, 48, 00, A3, E0, 75, A4, 00, E8, F2, 0B, 03, 00, E8, DD, FC, 02, 00, E8, 52, E2, 02, 00, E8, CA, D4, 02, 00, E8, 0E, C8, 02, 00, E8, FA, C4, 02, 00, E8, E8, C2, 02, 00, E8, B1, AA, 02, 00, E8, A0, A5, 02, 00, E8, B5, 94, 02, 00, E8, 38, 88, 02, 00...
 
[+]

Packer / compiler:
PKLITE32, 0x1.1

Code size:
404.5 KB (414,208 bytes)

The file kmsauto.exe has been seen being distributed by the following URL.

Remove kmsauto.exe - Powered by Reason Core Security