Cracked software, keygens and activators: what they really install
Cracks, keygens, activators and game cheats are among the most common ways malware reaches home PCs, because they come from anonymous sources and ask you to switch off your antivirus first. If you ran one, assume your saved passwords may have been copied, protect your accounts from another device and scan the PC offline.
- What cracks, keygens, activators and cheats are
- Why they are such a good carrier for malware
- What actually comes with cracks
- Why your antivirus flags a crack, and what the names mean
- Signs that a crack installed something
- What to do if you ran a crack, keygen or activator
- Safer ways to get the software you need
- Common myths about cracks
What cracks, keygens, activators and cheats are
All of these tools exist to make paid software or games behave as if they were licensed, or to give an unfair advantage in online games. They work by changing program files, patching memory or faking the licence check.
- Crack or patch: a modified program file, or a small tool that modifies one, so that the licence check is skipped.
- Keygen: a program that generates registration keys that the software will accept.
- Activator: a tool that activates Windows or Office without a valid licence, often by emulating a KMS server, the system that companies use to activate their own PCs. Microsoft Defender detects common ones as
HackTool:Win32/AutoKMSand similar names. - Loader: in the piracy world, a program that starts the real software and patches it in memory. (Security researchers use "loader" differently: for malware that downloads more malware.)
- Repack: a pirated game or program, compressed and bundled with its crack in one installer.
- Game cheats, trainers and mod menus: tools that change a game's memory or files; many need administrator rights or a driver.
Not every crack is malicious in itself. The problem is that you cannot tell which ones are, because the people who make and share them answer to no one, and the tools need exactly the access that malware wants.
Why they are such a good carrier for malware
Malware authors do not need to trick anyone into running an unknown program when people are already searching for one, downloading it from an anonymous site and running it as administrator. Microsoft's guidance on preventing malware names pirated software and the sites that offer it as a common source of infection, both through bundled malware and through the sites themselves.
The "turn off your antivirus" instruction
Almost every crack comes with a note: antivirus programs will flag it as a "false positive", so disable real-time protection, add an exclusion for the folder or switch off Tamper Protection before running it. Sometimes the claim is half true, because a genuine crack does modify software and gets a hacktool detection. But the instruction is identical whether the file is a harmless patch or a password stealer, and once protection is off nothing checks which one you have.
Password-protected archives
Cracks are often shared as ZIP, RAR or 7z archives with a password written on the download page or in a text file next to it. Security scanners cannot look inside an encrypted archive, and mail services and browsers cannot scan it on the way in. The password protects the malware from inspection, not you from anything.
Fake download sites, videos and search results
Many crack sites are not run by crackers at all. They are networks of pages built to rank for "[program name] crack free download", "full version" or "activator 2026", and they send every visitor to the same rotating malware, whatever program they asked for. Video tutorials that promise a free version of a paid program and link to a file in the description are used the same way, sometimes from hijacked channels. Shared links to cloud storage and file hosting services make the file look more trustworthy than it is.
Repacks and cheats run with full rights
Installers and game cheats usually ask for administrator rights, and some cheats install drivers so that they can read game memory. Anything bundled with them gets the same rights, which makes it easy to switch off security tools, add exclusions and hide.
What actually comes with cracks
Security vendors and Microsoft report the same handful of payloads again and again:
- Information stealers. The most common payload today. They copy saved browser passwords, cookies, autofill data, crypto wallets, messenger and gaming sessions, and documents, and send them off within minutes, often before you have finished installing the program. See information stealers.
- Cryptominers. They use the processor or graphics card to mine cryptocurrency for someone else. The PC gets slow, hot and loud. Games and repacks are a favourite carrier because gaming PCs have strong graphics cards. See cryptominers on Windows.
- Ransomware. Some ransomware families have spread mostly through cracks and keygens for years; the STOP/Djvu family, which encrypts personal files on home PCs, is the best-known example. See how ransomware works.
- Loaders and remote access trojans. They give the attacker a way back in and install whatever pays best later. See trojans and loaders and remote access trojans.
- Adware, browser hijackers and unwanted programs. Bundled installers on crack sites add extensions, change the search engine or install "optimizers". See potentially unwanted programs.
- Proxyware. Programs that rent out your internet connection to others, so that criminal traffic appears to come from your address.
It is common to get more than one at once: a loader brings a stealer, then a miner, then something else a week later. That is why cleaning up after a crack is about more than deleting the crack.
Why your antivirus flags a crack, and what the names mean
Detections on cracks fall into two groups, and they mean very different things.
- Tool or riskware names such as Microsoft's
HackTool:Win32/...orHackTool:Win64/AutoKMS, Kaspersky'snot-a-virus:RiskTool, or ESET's "potentially unsafe application". These say the file modifies software or licences. They do not say the file is harmless; they say its main job is not a typical malware job. - Malware names such as
Trojan:Win32/...,PWS:Win32/...(password stealer),Trojan:Win32/CoinMiner,Ransom:Win32/..., or another vendor'sTrojan.GenericKDorGen:Variant. These say the scanner found malicious code or behaviour.
A crack can carry both: the patch gets a hacktool name and the stealer packed next to it gets a trojan name. If any malware name appears, act on it. More on how vendors name the same threat: why antivirus programs give one threat different names.
Uploading a crack to a multi-engine scanner and seeing only a few hacktool detections does not prove it is clean. Many payloads are downloaded only after the crack runs, so the file you scanned is not the file that does the damage.
Signs that a crack installed something
- Windows Security is off, or shows exclusions you did not add, in Windows Security > Virus & threat protection > Manage settings > Exclusions.
- Protection history in Windows Security lists threats that were found and allowed, or that keep coming back.
- The PC is slow, fans run at full speed when idle, or the graphics card is busy with no game open: typical of a miner.
- New programs in Settings > Apps > Installed apps, new extensions in the browser, or a changed search engine.
- New entries in Task Manager > Startup apps or new tasks in Task Scheduler with random names or paths in
%AppData%or%Temp%. - Sign-in alerts from Google, Microsoft, Steam, Discord or your bank, sessions you do not recognise, or messages sent from your accounts.
- Crypto missing from a wallet, or a clipboard that changes a copied wallet address.
No signs at all does not mean nothing happened. Stealers do their work once and often delete themselves afterwards.
What to do if you ran a crack, keygen or activator
Assume the worst until you have checked, especially if you followed instructions to disable your antivirus.
- Disconnect from the internet if you suspect a stealer or a remote access tool, to stop more data leaving and more malware arriving.
- Protect your accounts from another device first. Change the password of your main e-mail account, then banking, Microsoft, Google, Steam, Discord, social media and any crypto exchange, and sign out of all sessions on each. Move crypto to a new wallet created on a clean device. Order and details: securing your accounts after malware.
- Turn protection back on. In Windows Security > Virus & threat protection > Manage settings, switch on Real-time protection, Cloud-delivered protection and Tamper Protection, and remove exclusions you did not choose yourself.
- Uninstall the cracked program and anything that came with it, sorting Installed apps by install date: Uninstall a program or app in Windows On uGetFix.
- Run a full scan, then an offline scan, which works before Windows starts so that hidden malware cannot interfere: Run a Microsoft Defender Offline scan.
- Check startup entries and scheduled tasks for leftovers and turn them off: Stop apps from opening at startup On uGetFix.
- Turn on two-step verification for the accounts that matter: Turn on two-step verification / secure a hacked account.
If Windows itself was activated with a KMS activator, the activator may also have installed a service or scheduled task that runs on its own; the scans above usually find it. Activate Windows with a genuine licence in Settings > System > Activation afterwards.
If files were encrypted, follow Ransomware: first steps, finding a decryptor and recovering files instead. If a remote access tool was found, security settings kept switching off, or detections return after every clean-up, resetting Windows is the safer option: clean up or reset Windows after malware.
Safer ways to get the software you need
- Free and open-source alternatives exist for most everyday programs: office suites, image and video editors, 3D tools, audio editors, archivers and PDF tools.
- Free tiers, trials, education and non-commercial licences are offered by many paid programs. Students and teachers can often get professional software free.
- Sales and bundles from official stores bring games and programs down to a fraction of the full price.
- Windows itself keeps working without activation, with a watermark on the desktop and personalisation settings locked, so there is no need for an activator while you decide. A genuine licence is cheaper than recovering from a stolen bank account.
- Download only from the developer's site, the Microsoft Store, Steam or another official store. Check the address before you download; fake "official" sites buy search ads.
If you still decide to use a crack, at least never switch off your antivirus for it, never run it on the PC where you do your banking or keep a crypto wallet, and treat every account used on that PC as at risk.
Common myths about cracks
- "It's a false positive, every crack gets flagged." Some flags are tool detections, but the same excuse is used to deliver stealers. A trojan, stealer or ransomware name is not a false positive.
- "It came from a well-known release group." Malware sites copy release group names and file names. You cannot verify where a file really came from.
- "I scanned it on VirusTotal and only a few engines flagged it." Many cracks download the real payload after they run, and new payloads are not yet known to most engines.
- "Nothing happened, the program works fine." That is the plan. Stealers run once, in the background, and the program works so that you do not look further.
- "I use a VPN, so I'm safe." A VPN hides your connection, not what you run. It does nothing against malware you start yourself.
- "Game cheats are different." Cheats often need administrator rights or drivers, and gaming accounts and skins are valuable, which makes cheats a favourite carrier for stealers.
- Information stealers: what they take from a Windows PC and how fast
- Cryptominers on Windows: signs, hiding tricks and removal
- Securing your accounts after malware or phishing: the order that matters
- Potentially unwanted programs and bundled installers explained
- Why antivirus programs give one threat different names
Frequently asked questions
Are cracked programs always infected?
Not always, but you cannot tell which ones are, and the risk is high. A crack modifies software, so security programs flag it either way, and the people sharing it ask you to switch off protection, which removes the one check that could tell a harmless patch from a stealer. Many crack sites exist only to spread malware and serve the same payload whatever you searched for. Microsoft lists pirated software among the common sources of infection. If you need a program you cannot afford, a free alternative, a trial or an education licence avoids the problem entirely.
Is HackTool:Win32/AutoKMS a virus?
AutoKMS is Microsoft's detection name for tools that activate Windows or Office without a valid licence by imitating a company activation server. Microsoft classes it as a hacktool rather than a virus, because its main job is to bypass licensing. That does not make it safe: activators change system services and scheduled tasks, run with full rights and come from unofficial sources, and some downloads named after popular activators carry real malware too. Remove it, run a full and an offline scan to check nothing else came with it, and activate Windows with a genuine licence.
The crack told me to disable my antivirus. What should I do now?
Turn protection back on straight away: open Windows Security, go to Virus & threat protection > Manage settings, and switch on Real-time protection, Cloud-delivered protection and Tamper Protection. Then check Exclusions in the same place and remove any folder or file you did not add yourself, since malware often adds itself there. Run a full scan and a Microsoft Defender offline scan. Because the protection was off while the crack ran, change your important passwords from another device and sign out of all sessions, as you would after any information stealer.
Can a keygen steal my passwords?
The key-generating code itself does not need to, but keygens are one of the most common wrappers for information stealers. A stealer packed with a keygen runs once in the background, copies saved browser passwords, cookies, autofill data, crypto wallets and gaming or messenger sessions, sends them to the attacker and often deletes itself, while the keygen shows a normal key on screen. If you ran a keygen, assume your saved passwords were copied: change them from another device, sign out of all sessions and turn on two-step verification, then scan the PC.
Will reinstalling the program or deleting the crack remove the malware?
No. Deleting the crack removes only the crack. Anything it installed lives elsewhere: a startup entry, a scheduled task, a service, a browser extension or files in AppData. Reinstalling the program does not touch those either. Run a full scan and a Microsoft Defender offline scan, check Startup apps, Task Scheduler and Installed apps for anything new, and remove exclusions in Windows Security. Data already stolen cannot be removed from the attacker's hands, so the account steps still apply. If detections keep returning after a clean-up, a Windows reset is the faster and safer fix.
Are game cheats and mod menus safe?
Treat them like cracks. Many cheats need administrator rights or install a driver so that they can read game memory, and anything bundled with them gets the same access. Gaming accounts, skins and in-game items can be sold, which makes players an attractive target for stealers, and cheat downloads are a common way to reach them. Cheats also break most games' rules and can get your account banned. Mods from the game's official workshop or a well-known mod platform with user reviews are a much lower risk than executables from forums and video descriptions.
Can cracked software cause ransomware?
Yes. Some ransomware families have spread mainly through cracks, keygens and pirated installers aimed at home users, STOP/Djvu being the best-known one. It encrypts photos and documents and adds a new extension to every file. Other cracks install a loader that brings ransomware later. If your files suddenly have a new extension and a ransom note appeared, disconnect the PC from the network and follow Ransomware: first steps, finding a decryptor and recovering files. A 3-2-1 backup with one copy kept offline is the only reliable way to get files back without paying.
Sources
- Microsoft Learn: Prevent malware infection (pirated material, removable drives) (read 4 October 2026)
- Microsoft Security Intelligence: HackTool:Win32/AutoKMS threat description (read 4 October 2026)
- Microsoft Learn: Coin miners (read 4 October 2026)
- Microsoft Learn: Microsoft Defender malware naming (read 4 October 2026)
- Broadcom (Symantec) Protection Bulletin: STOP / DJVU ransomware still observed in the wild (read 4 October 2026)
Ugnius Kiguolis, Owner and editor of 2-spyware.com. Ugnius Kiguolis owns and edits 2-spyware.com and is responsible for its Windows security guides. Every page he signs is checked against current vendor, law-enforcement and Microsoft sources before it is published and again when the facts change.