HackTool:Win32/AutoKMS always return

EP 0 Reputation points
2026-08-26T13:02:39.53+00:00

Hi.

I clear it (HackTool:Win32/AutoKMS) with Win Defender Offline and after it's always "quarantine failure" and "status: rejected/deniel" (I translate it I don't know how it right on english writed).

Thank you.

Windows for home | Other | Security and privacy
0 comments No comments

2 answers

Sort by: Most helpful
  1. Ramesh 180.3K Reputation points Volunteer Moderator
    2026-08-26T16:12:57.4466667+00:00

    Please share your Farbar scan logs for analysis.

    • Download Farbar Recovery Scan Tool 64-bit FRST64.exe
    • If the OS language is not English, rename FRST64.exe to FRST64English.exe.
    • Run the program. Don't check or uncheck any options. Click "Scan".
    • Add the two logs, FRST.txt and Addition.txt, to a zip archive.
    • Share the zip file on OneDrive or GoFile.io, and post the link here.

    Note: If Microsoft Edge or Chrome mislabels the Farbar Scanner executable as PUA/malware, choose to keep it by tapping … in the bottom bar, choosing Keep, and then choosing Keep anyway in the dialog that appears. See this screenshot. It's a safe tool used in most antimalware forums.


    Was this answer helpful?

    0 comments No comments

  2. AI answer

    2026-08-26T13:02:59.86+00:00

    If the same threat keeps returning after quarantine or an offline scan, the most likely causes in the available guidance are:

    • the file was only partially removed
    • another hidden malware component is reinstalling it after restart
    • the item is still only quarantined, not fully removed

    Recommended steps:

    1. Run the Malicious Software Removal Tool first:
      • Press Windows key + R
      • Type %windir%\system32\mrt.exe
      • Select OK
      • If prompted, select Yes
      • Follow the prompts to scan and clean the PC
    2. Restart the PC.
    3. Install the latest Windows updates.
    4. Run Microsoft Defender Offline again:
      • Go to Start > Settings > Update & Security > Windows Security > Virus & threat protection
      • Under Current threats, select Scan options
      • Select Windows Defender Offline scan
      • Select Scan now
    5. Check Protection history / Threat history:
      • Go to Start > Settings > Update & Security > Windows Security > Virus & threat protection
      • Open Threat history
      • If the item is listed as Threat quarantined, choose Remove to delete it from the device
      • Do not choose Allow unless the file is fully trusted, because that lets it run again
    6. If Defender keeps showing scan or removal errors, run Windows Update and, if needed, install the latest protection updates manually.

    Important:

    • Quarantine blocks the file so it cannot run, but it is not the same as permanent removal.
    • If the threat reappears right after restart, that matches Microsoft guidance for malware that is being silently reinstalled by another hidden component.
    • Defender Offline restarts the PC before scanning, so save work first.

    If the PC has already been changed or damaged by the malware and cleanup does not succeed, the documented recovery path is to reset, restore, or reinstall Windows, preferably restoring files from backups created before the infection.


    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.