cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
dilan90
Level 9
Report Inappropriate Content
Message 1 of 3

ENS unable to Detect and Delete a threat

Jump to solution

Hi,

Can anyone explain why below file in not getting detect & delete by ENS threat prevention. Some third party AV's can detect below file as per the attached image

File-06

File: Install_Service.cmd

Recommendation:          This item should be removed.

 

File Details:

 Path:     C:\Program Files\KMSpico\scripts\Install_Service.cmd

 SHA256:  11578521B14C17FBBB070C13887161586D57196F4D408C41A0F02ED07EE32F2C        MD5:     9107CD31951F2CF90E0892740B9087C9

 

File Reputation: There are many indications that this file is untrustworthy.

 

File Score:           -500

 

                Test       Result   Score     Details

What is the file's reputation?      Untrustworthy  -500       There are many indications that this file is untrustworthy.

The file is present for many users.

The file was first seen 03-01-2016

Is the file's signature valid?          N/A        0              File cannot be signed

 

Thanks

Dilan

Trellix Endpoint Security  

Labels (1)
1 Solution

Accepted Solutions

Re: ENS unable to Detect and Delete a threat

Jump to solution

I just looked at the file contents and I don't think that is really malicious.   It references the following:

sc create %name% binPath= "%dr%Service_KMS.exe" type= own error= normal start= auto DisplayName= %name%

So unless service_kms.exe is bad,  there is nothing wrong here. 

Dave

Dave

View solution in original post

2 Replies

Re: ENS unable to Detect and Delete a threat

Jump to solution

I just looked at the file contents and I don't think that is really malicious.   It references the following:

sc create %name% binPath= "%dr%Service_KMS.exe" type= own error= normal start= auto DisplayName= %name%

So unless service_kms.exe is bad,  there is nothing wrong here. 

Dave

Dave

dilan90
Level 9
Report Inappropriate Content
Message 3 of 3

Re: ENS unable to Detect and Delete a threat

Jump to solution

Hi @Daveb3d

Thanks for the respond on this

 

 

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use our Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from product experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by employees.
Join the Community
Join the Community