Gridinsoft Logo
File Icon

OInstall_x64.exe Hack AutoKMS Analysis

Technical Analysis

File Name OInstall_x64.exe
File Type
PE32+ executable (GUI) x86-64, for MS Windows
Scanner Version 1.0.209.174
Database Version 2025-03-02 08:00:28 UTC

Hack.Win64.AutoKMS.cl

Malware family: AutoKMS

AutoKMS is a tool associated with illegal Microsoft software activation that bypasses legitimate licensing processes. It introduces security risks and potential legal consequences.
N/A
Detection Rate
17,888,256
File Size (bytes)
2025-03-02
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
a3e624e871b3aab47b569b42d424a94e
SHA1
f0516f374a08f0e1953c011746ec3704c02fc09e
SHA256
a72a7e24885c82b720e7d33e496370ab4b4a1d1e43fc45a97dbf4642f8cd24f8
SHA512
b827d7a5ee9085498b0d6f032c88348f2ef5d45fd5e7cd51942c7e12b27f2652750d69ed3ecb535758606f7b6ce7b1d01adb055fc0fb1f8e19ec0ceb99b48457
ImpHash
22b8b9e075a02ede188dfa018080ed49

PE Analysis

Basic Information

Icon
Hash: cf8b3d44cc80ac3d3f5b2c3f6848133a
Fuzzy: 71fcd2e860bbcd562ce257f969072383
dHash: e0c8ccc6c6c6c0e0
Image Base 0x140000000
Entry Point 0x140001000
Compilation Time 2024-09-27 14:08:40
Checksum 0x01111bfd (Actual: 0x01111bfd)
OS Version 5.0
PEiD Signatures PE32+ executable (GUI) x86-64, for MS Windows
Digital Signature No valid SignedData structure was found.
Imports 14 libraries
Exports 0 functions
Resources 7 Resources
Sections 7 Sections

Version Information

ProductName Office 2013-2024 C2R Install
FileDescription Office 2013-2024 C2R Install
Translation 0x0000 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.code 0x00001000 564,969 bytes 565,248 bytes 5.83 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 6431C897C6DFBC15E4A27DC614EF8938
.text 0x0008b000 902,739 bytes 903,168 bytes 6.50 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ CBE53F90F6C9D2384FE2EFA023C85673
.rdata 0x00168000 234,128 bytes 234,496 bytes 5.92 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 365B57518ACE17AB8DB72FC720B39064
.pdata 0x001a2000 40,944 bytes 40,960 bytes 6.14 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ EAEC2610803CE96F1C89318B98AC086E
.data 0x001ac000 16,563,944 bytes 16,055,296 bytes 7.03 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 1DC28EBC055FF44500376EFFEAC0472A
.rsrc 0x01178000 87,756 bytes 88,064 bytes 2.17 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 72EA6CA31E8D5C51FB0C768284C73B32
.modplug 0x0118e000 20,480 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
Entropy Analysis Alert

2 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 7 (87,303 bytes)
Resource Type Count Total Size Percentage
RT_ICON 4 82,656 bytes
94.7%
RT_GROUP_ICON 1 62 bytes
0.1%
RT_VERSION 1 412 bytes
0.5%
RT_MANIFEST 1 4,173 bytes
4.8%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Hack.Win64.AutoKMS.cl Removal

Gridinsoft has the capability to identify and eliminate Hack.Win64.AutoKMS.cl without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware