Hi,
Can anyone explain why below file in not getting detect & delete by ENS threat prevention. Some third party AV's can detect below file as per the attached image
File-06
File: Install_Service.cmd
Recommendation: This item should be removed.
File Details:
Path: C:\Program Files\KMSpico\scripts\Install_Service.cmd
SHA256: 11578521B14C17FBBB070C13887161586D57196F4D408C41A0F02ED07EE32F2C MD5: 9107CD31951F2CF90E0892740B9087C9
File Reputation: There are many indications that this file is untrustworthy.
File Score: -500
Test Result Score Details
What is the file's reputation? Untrustworthy -500 There are many indications that this file is untrustworthy.
The file is present for many users.
The file was first seen 03-01-2016
Is the file's signature valid? N/A 0 File cannot be signed
Thanks
Dilan
Solved! Go to Solution.
I just looked at the file contents and I don't think that is really malicious. It references the following:
sc create %name% binPath= "%dr%Service_KMS.exe" type= own error= normal start= auto DisplayName= %name%
So unless service_kms.exe is bad, there is nothing wrong here.
Dave
Dave
I just looked at the file contents and I don't think that is really malicious. It references the following:
sc create %name% binPath= "%dr%Service_KMS.exe" type= own error= normal start= auto DisplayName= %name%
So unless service_kms.exe is bad, there is nothing wrong here.
Dave
Dave
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.
Thousands of customers use our Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership: