Is Keygen.exe safe?
Only 2 of 74 engines detected this unsigned, rarely observed key generator, but absent runtime coverage and weak provenance leave meaningful uncertainty.
Two of 74 engines raised generic detections, while all reporting tier-1 engines remained silent and no malware family achieved consensus. However, the executable is unsigned, rarely observed, and lacks completed runtime and contacted-host reputation coverage, so it should not be run on a production system.
e0e2a7b718ab2d176f…b6319473484c09Recommended next actions
Before running
Do not run it until the source and publisher can be verified independently.
If you already ran it
Stop using it, scan the device, and watch for unexpected behavior or security alerts. Get a fresh copy from the developer's official site or an official app store.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
Two of 74 engines raised generic detections, while all reporting tier-1 engines remained silent and no malware family achieved consensus. However, the executable is unsigned, rarely observed, and lacks completed runtime and contacted-host reputation coverage, so it should not be run on a production system.
The scan contains two generic detections among 74 engines, with no tier-1 engine identifying malware and no family consensus. That pattern has a substantial chance of being a false positive, particularly because the executable is neither packed nor associated with offensive MITRE techniques in the available evidence. Confidence in benignity is limited because the file is unsigned and has appeared in only two submissions. No completed sandbox observation is available, and contacted-host reputation was not checked or saved. Similar-file history is mixed and consists entirely of imphash-only matches without signer co-matches, so it provides little dependable reassurance.
What We Detected
Two of 74 antivirus engines flagged the executable. APEX supplied a generic malicious label, while BitDefenderTheta supplied the generic machine-learning label “Gen:NN.ZemsilCO”; no tier-1 engine flagged it and no named malware family reached consensus.
Threat Behavior
No completed sandbox run is available, so runtime behavior cannot be characterized. Static analysis found no likely packing or high-entropy code, and no offensive MITRE techniques were recorded. Contacted-host reputation was not checked or saved, so no complete network-reputation conclusion is available.
What To Do Now
Avoid executing this unsigned key generator on a production or personal system. Keep endpoint protection enabled, obtain software through its legitimate publisher, and quarantine the file unless its origin and purpose can be independently verified.
Where this verdict could be wrong3 caveats
- BitDefenderTheta is a tier2 engine and reported a generic neural-network detection, so the two detections cannot be dismissed as entirely low-trust noise.
- The filename 'Keygen.exe' indicates a software-key generator, a class frequently associated with unwanted or malware-bundled distribution, although engines.hacktoolConfirmed=false.
- The file wrote 'udhisapi.dll' beneath a Windows service-profile path, but behaviour.sandboxCount=0 prevents treating this artifact as completed runtime evidence.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- No tier-1 engine detections
- No engine family consensus
- No confirmed hacktool labeling
- No likely packing or high-entropy code
- No offensive MITRE techniques in available evidence
- Unsigned Win32 executable with no authenticated publisher
- Only two submissions from two sources despite being several years old
- Generic detections from APEX and BitDefenderTheta
- No completed runtime observation
- No complete contacted-host reputation result
- Filename indicates software-key-generation functionality
Do not run the file unless its source and exact function can be independently verified; prefer properly licensed software from the official publisher. Keep antivirus and endpoint protection enabled and quarantine or delete the sample if verification is unavailable.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete2 of 74 engines flagged the file.
Sandbox
PartialRuntime data is present, but no completed sandbox environment is recorded.
Network
Not runNo contacted-host reputation check is recorded.
No timestamp recordedYARA
CompleteRule evaluation completed with no recorded matches.
External intel
PartialIndependent reference checks were attempted but are incomplete.
Behavior
Plain-English impact first, then the observed runtime evidence.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
Keygen.exe
e0e2a7b718ab2d176ffafaf4c14fce44d4b131f453c6cdf880b6319473484c09
01Uploaded file
Files
Created or changed
- Written fileObserved
udhisapi.dll
C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
02Isolated runtime analysis
2 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
Runtime behavior was not available
The report does not treat a missing runtime observation as a clean result.
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 0rule hits recorded
- 2 / 74engines flagged
- 2sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
2 of 74 antivirus engines flagged the file, including APEX and BitDefenderTheta.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has been submitted 2 times from 2 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 03
Scanned file: Keygen.exe — e0e2a7b718ab2d176ffafaf4c14fce44d4b131f453c6cdf880b6319473484c09
ProvenanceObservedSourceUploaded fileObserved at - 04
File written: udhisapi.dll — C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
Available reference checks returned no match, but at least one source was unavailable. This is not a clean result.
YARA rules
No matchesThe rule pass completed without a saved public match.
2 of 74 engines flagged this file
View all 74 engine results
Section entropy & packers
No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.
How widely this file has been seen
Rarely uploaded, but has been around for a while. Often niche legitimate software or old internal tooling; not a strong malware signal on its own.
Fingerprint and provenance
- File name
- Keygen.exe
- Format
- Win32 EXE
- Code signing
- No verified publisher
- Size
- 20.0 KB
- Last analyzed
- Sep 8, 2026, 3:26 PM UTC
e0e2a7b718ab2d176ffafaf4c14fce44d4b131f453c6cdf880b6319473484c09Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
We couldn't fully clear this file. Treat it with caution.
- Recovery step 01
Don't run it unless you're certain it came from a source you trust.
- Recovery step 02
Check where you got it — an unexpected attachment or a random download link is a red flag.
- Recovery step 03
If its origin cannot be confirmed, delete this file and use a fresh copy from a trusted source. Get a fresh copy from the developer's official site or an official app store.
- Recovery step 04
If you're still unsure, scan it again in a day or two — detections often catch up on newer files.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is Keygen.exe safe, or is it malware?
What is Keygen.exe?
How many antivirus engines detected Keygen.exe?
I already downloaded and ran Keygen.exe — what should I do?
How do I remove Keygen.exe?
What is the SHA-256 hash of Keygen.exe?
How up to date is this analysis of Keygen.exe?
Community
Member reviews and reports for this exact file hash.