Advice Request Windows 10 : Defender found a threat HackTool:Win32/AutoKMS.

Please provide comments and solutions that are helpful to the author of this topic.

Tessy

Level 1
Thread author
Feb 14, 2019
8
I recently brought a laptop lenovo i3 4gb/1tb with pre installed genuine windows 10. Windows defender now detected a threat called Hacktool:win32/autokms. What to do now ?
 
  • Like
Reactions: Vasudev

SHvFl

Level 35
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Nov 19, 2014
2,345
Your windows or office was activated using an "illegal" activation tool. That is the most logical explanation but other possibilities might be there.
You need to clean install windows as the seller you bought seems shady and other goodies might be hiding. Issue might be activation but it's the only way. If you bought from a person you know ask them if they activated windows with autoksm or if you bought from a store tell them you need a proper windows license as the machine is illegally activated (assuming you didn't know that).
 

Tessy

Level 1
Thread author
Feb 14, 2019
8
Your windows or office was activated using an "illegal" activation tool. That is the most logical explanation but other possibilities might be there.
You need to clean install windows as the seller you bought seems shady and other goodies might be hiding. Issue might be activation but it's the only way. If you bought from a person you know ask them if they activated windows with autoksm or if you bought from a store tell them you need a proper windows license as the machine is illegally activated (assuming you didn't know that).
Could Windows defender removes this threat? Instead of clean installing windows?
 
  • Like
Reactions: shmu26 and RXZ6Q

SHvFl

Level 35
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Nov 19, 2014
2,345
Could Windows defender removes this threat? Instead of clean installing windows?
It will if you click remove in wd defender but you don't know what else the seller stupidly did. I wouldn't risk it.
If he told you windows is activated not in a legit way before you bought then you will probably be fine by just removing this detection but if not don't trust him.
 

Tessy

Level 1
Thread author
Feb 14, 2019
8
It will if you click remove in wd defender but you don't know what else the seller stupidly did. I wouldn't risk it.
If he told you windows is activated not in a legit way before you bought then you will probably be fine by just removing this detection but if not don't trust him.
Thanks. Actually they told me this model is coming with pre installed genuine windows. They probably installed the other softwares.
 
  • Like
Reactions: shmu26 and Vasudev

TairikuOkami

Level 35
Verified
Top Poster
Content Creator
Well-known
May 13, 2017
2,486
Actually they told me this model is coming with pre installed genuine windows.
It might have came with Windows 8 or 7, but they clean installed 10 and it did not activate, so they cheated it by using KMS instead of trying to activate it properly. Or maybe they have installed Pro and your laptop has OEM licence only for Home. What model do you have exactly?
 

Tessy

Level 1
Thread author
Feb 14, 2019
8
They scammed you then assuming you didn't do anything weird with microsoft office yourself. autoksm is an illegal activation method.
It might have came with Windows 8 or 7, but they clean installed 10 and it did not activate, so they cheated it by using KMS instead of trying to activate it properly. Or maybe they have installed Pro and your laptop has OEM licence only for Home. What model do you have exactly?
I have Lenovo i3 4gb/1tb 8th generation laptope
 

LoLs

Level 2
Verified
Dec 16, 2016
98
i forgot to mention since you're saying that your laptop is pre installed with genuine windows 10
please check
  1. Tap on the Windows-key, type cmd.exe and hit enter.
  2. Type slmgr /xpr and hit enter.
you should see "the machine is permanently activated "

i take this screenshot from my windows so you can compare

P1UCxg4.jpg


if you see something shows like kms rearm with date, than your Windows OS activation is not genuine or have been tampered with that tool.
 

Vasudev

Level 33
Verified
Nov 8, 2014
2,230
Thanks. Actually they told me this model is coming with pre installed genuine windows. They probably installed the other softwares.
Office license isn't included, only OS license is pre-installed in mobo by Lenovo.
Check downloads folder. AutoKMS isn't that harmful when comparing Ransomwares. I use them quite often for quick rearm to test out Windows Softwares and I hate seeing Windows or Office isn't activated screen.
If you find an Office License key for cheap buy it and activate the product key using AutoKMS, you can use Phone or online activation if you live in a region where Skype and others are banned by Govt.
 
  • Like
Reactions: RXZ6Q

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
You can check the windows activation status. If it says your Windows is activated with a digital license linked to your machine, then it is legit, it is not from the KMS. If this is the case, then the KMS is for Office, not for Windows, and the sellers told you the truth and are probably reliable people. But @SHvFl's advice is still the safest course to follow.
 

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
How can I learn more about these new pirating methods for Windows activation?
I don't need it personally, because I have a legal licence for my Windows systems, but I am curious to know about it.
In any case, a KMS activation will not show that Windows is activated with a digital license linked to your machine. It is a different message, I don't remember what it says. I think it says something like Windows is activated by your organization.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top