• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Groups
  • Search
  • Register
  • Login
TRIGGERcmd
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Groups
  • Search
  • Register
  • Login

Kaspersky Detects TriggerCMDAgent.exe as Win32.BSS.ScreenLock

General Discussion
2
7
399
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • ?
    A Former User
    last edited by May 21, 2020, 11:09 AM

    Hello, I'm using Kaspersky Total Security, and it's deleted c:\users\xxx\appdata\local\triggercmdagent\app-1.0.22\triggercmdagent.exe as Win32.BSS.ScreenLock and deleted it.

    Any insight?

    Thank you

    R 1 Reply Last reply May 21, 2020, 11:42 AM Reply Quote 0
    • R
      Russ @A Former User
      last edited by Russ May 21, 2020, 11:47 AM May 21, 2020, 11:42 AM

      @Lewis-S, it's a false positive unless the exe has been manipulated. If you have another PC with TRIGGERcmd you could copy the exe from it and do a file compare with the fc command. That assumes Kapersky moved it to quarantine rather than deleting it.

      If you confirm it's the same, you can exclude it from scanning, and ideally report the false positive to Kapersky.

      Later today I'll see if I can get a copy of Kapersky to try a scan.

      Russell VanderMey

      1 Reply Last reply Reply Quote 0
      • ?
        A Former User
        last edited by May 21, 2020, 12:27 PM

        I'll redownload it and see if It redetects if i scan it.

        I'll report as false positive.

        Thanks!

        1 Reply Last reply Reply Quote 0
        • ?
          A Former User
          last edited by A Former User May 21, 2020, 6:57 PM May 21, 2020, 6:56 PM

          hey @Russ ,
          It's having a right fit about TriggerCMD making TCP connections, and running Command Host processes!

          I've allowed it to do all these, there was lots of these boxes to allow!
          9d2fcd97-9b7d-4e0b-a072-91404e49e7c1-image.png

          I'm unsure why only now it decides that TriggerCMD is not okay!

          R 1 Reply Last reply May 21, 2020, 10:33 PM Reply Quote 0
          • R
            Russ @A Former User
            last edited by Russ May 21, 2020, 10:35 PM May 21, 2020, 10:33 PM

            @Lewis-S, I don't know. Maybe Kaspersky has heuristics that noticed the agent running commands it thought were suspicious. Not necessarily on your computer, but it ended up in their database as a suspicious exe. Just a theory.

            Russell VanderMey

            ? 1 Reply Last reply May 24, 2020, 9:05 PM Reply Quote 0
            • ?
              A Former User @Russ
              last edited by May 24, 2020, 9:05 PM

              @Russ I would say so.

              It's uninstalled it again for me at some point so I'll need to find a way to trust TriggerCMD.

              R 1 Reply Last reply May 24, 2020, 11:37 PM Reply Quote 0
              • R
                Russ @A Former User
                last edited by May 24, 2020, 11:37 PM

                @Lewis-S, I see a "Apply always" option on your screenshot. That might prevent it from deleting the .exe. You could also exclude that folder from scans.

                Russell VanderMey

                1 Reply Last reply Reply Quote 0
                2 out of 7
                • First post
                  2/7
                  Last post