Should I block it?

98%
Yes, 98% block recommendation.
Possible reason:
Multiple malware detections

VersionsAdditional versions

2.5.0.0 1.27%
2.5.0.0 1.27%
2.4.9.0 3.80%
2.4.7.0 1.27%
2.4.3.0 13.92%
2.2.2.0 34.18%
2.2.0.0 1.27%
2.1.6.0 8.86%
2.1.5.0 1.27%
2.1.3.0 3.80%
2.0.0.0 2.53%
2.0.0.0 20.25%
2.0.0.0 6.33%

AutoKMS.exe

AutoKMS

Remove AutoKMS.exe
Version:   2.0.0.0
MD5:   df608bdb810684df278ba5e0c38c8885
SHA1:   66a815e5ebc64c21f961bf031f8d701881603b0d
SHA256:   f54d1cfc816e1a78d2c4edfe85a2d14064dfb796a3f7e67f8420a7b29219a3e3
Warning 31 antivirus scanners has detected malware.

Overview

autokms.exe is set to be start when the PC boots and any user logs into Windows (added to the Run registry key for the all users under the local machine). The assembly utilizes the .NET run-time framework (which is required to be installed on the PC).

DetailsDetails

File name:autokms.exe
Product name:AutoKMS
Typical file path:C:\windows\autokms\autokms.exe
File version:2.0.0.0
Size:601.5 KB (615,936 bytes)
Digital DNA
File packed:No
Code language:Microsoft Visual C# / Basic .NET
.NET CLR:Yes
.NET NGENed:No
More details

BehaviorsBehaviors

Scheduled tasks
  • The job 'AutoKMSCustom' runs daily in the path '\AutoKMSCustom'
  • The task 'AutoKMSDaily' runs daily in the path '\AutoKMSDaily'
  • The job 'AutoKMS' runs daily in the path '\AutoKMS'
  • Entry path '\AutoKMSDaily'
  • Entry path '\AutoKMS'
  • Entry path 'C:\WINDOWS\Tasks\AutoKMS.job'
Scheduled tasks startups
Set to load on user login (bypasses Windows UAC if enabled)
  • Login entry path '\AutoKMS'
Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'AutoKMS' → C:\WINDOWS\AutoKMS.exe

MalwareMalware detections

Based on 40+ industry antivirus scanners, 31 of them detected the following malware.
Antivirus engineEngine versionDetection
Agnitum 5.5.1.3 Trojan.Meredrop!pMjFc1ZBsZw
Avira AntiVir 7.11.73.120 TR/Meredrop.A.8924
avast! 6.0.1289.0 Win32:PUP-gen [PUP]
AVG 2014.0.3629 Generic19.AVDB
BitDefender 7.2 Application.Keygen.BY
Commtouch 5.4.1.7 W32/Risk.IALF-3386
Comodo Internet Security 15977 UnclassifiedMalware
Emsisoft Anti-Malware 3.0.0.575 Application.Keygen.BY (B)
ESET NOD32 7.8243 Win32/HackKMS.A
Fortinet 5.0.43.0 W32/Dx.UQG!tr
F-Prot v6.4.7.1.166 W32/MalwareF.OISJ
F-Secure 11.0.19020.35 Application.Keygen.BY
G Data 13.4.22 Application.Keygen.BY
Ikarus T3.1.4.0.0 possible-Threat.Patch.KMS
K7 AntiVirus 9.164.8548 Riskware
K7GW 12.7.0.8 Riskware
Kingsoft 2013.4.9.267 Win32.Troj.Generic.a.(kcloud)
Malwarebytes 1.75.0.1 Riskware.Keygen
McAfee 5.400.1158 Generic.dx!uqg
McAfee Gateway Anti-Malware v2012.1-dat Generic.dx!uqg
Microsoft Security Essentials 1.9402.0 HackTool:Win32/Keygen
eScan by MicroWorld 12.0.250.0 Application.Keygen.BY
NANO AntiVirus 0.24.0.52049 Trojan.Win32.Meredrop.zevmu
Norman 7.00.22 Suspicious_Gen2.ENOUR
Panda Antivirus 10.0.3.5 Generic Trojan
PC Tools 9.0.0.2 Trojan.Gen
Sophos 4.88.0 Mal/Keygen-N
Symantec 20121.3.0.76 Trojan.Gen
Trend Micro 9.740.0.1012 CRCK_KEYGEN
Trend Micro HouseCall 9.700.0.1001 CRCK_KEYGEN
VIPRE Antivirus 16986 Trojan.Win32.Generic!BT

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Ultimate 32.91%
Windows 7 Home Premium 16.46%
Windows 8 7.59%
Windows 7 Professional 7.59%
Windows 8 Pro 7.59%
Windows 8.1 5.06%
Windows 8.1 Pro with Media Center 3.80%
Windows 8.1 Single Language 2.53%
Windows 8 Enterprise N 2.53%
Microsoft Windows XP 2.53%
Windows 7 Enterprise 2.53%
Windows 7 Starter 2.53%
Windows 8 Enterprise 2.53%
Windows 8.1 Pro 1.27%
Windows 8.1 Pro Preview with Media Center 1.27%
Windows 7 Home Basic 1.27%

Distribution by countryDistribution by country

United States installs about 11.39% of AutoKMS.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Lenovo 33.71%
ASUS 15.73%
Toshiba 13.48%
Acer 8.99%
Hewlett-Packard 7.87%
Intel 4.49%
Dell 4.49%
GIGABYTE 4.49%
American Megatrends 3.37%
Samsung 3.37%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE