TRIGGERcmd
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Groups
    • Search
    • Register
    • Login

    Kaspersky Detects TriggerCMDAgent.exe as Win32.BSS.ScreenLock

    Scheduled Pinned Locked Moved General Discussion
    7 Posts 2 Posters 870 Views 1 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • ? Offline
      [[global:former-user]]
      last edited by

      Hello, I'm using Kaspersky Total Security, and it's deleted c:\users\xxx\appdata\local\triggercmdagent\app-1.0.22\triggercmdagent.exe as Win32.BSS.ScreenLock and deleted it.

      Any insight?

      Thank you

      RussR 1 Reply Last reply Reply Quote 0
      • RussR Offline
        Russ @Guest
        last edited by Russ

        @Lewis-S, it's a false positive unless the exe has been manipulated. If you have another PC with TRIGGERcmd you could copy the exe from it and do a file compare with the fc command. That assumes Kapersky moved it to quarantine rather than deleting it.

        If you confirm it's the same, you can exclude it from scanning, and ideally report the false positive to Kapersky.

        Later today I'll see if I can get a copy of Kapersky to try a scan.

        Russell VanderMey

        1 Reply Last reply Reply Quote 0
        • ? Offline
          [[global:former-user]]
          last edited by

          I'll redownload it and see if It redetects if i scan it.

          I'll report as false positive.

          Thanks!

          1 Reply Last reply Reply Quote 0
          • ? Offline
            [[global:former-user]]
            last edited by [[global:former-user]]

            hey @Russ ,
            It's having a right fit about TriggerCMD making TCP connections, and running Command Host processes!

            I've allowed it to do all these, there was lots of these boxes to allow!
            9d2fcd97-9b7d-4e0b-a072-91404e49e7c1-image.png

            I'm unsure why only now it decides that TriggerCMD is not okay!

            RussR 1 Reply Last reply Reply Quote 0
            • RussR Offline
              Russ @Guest
              last edited by Russ

              @Lewis-S, I don't know. Maybe Kaspersky has heuristics that noticed the agent running commands it thought were suspicious. Not necessarily on your computer, but it ended up in their database as a suspicious exe. Just a theory.

              Russell VanderMey

              ? 1 Reply Last reply Reply Quote 0
              • ? Offline
                [[global:former-user]] @Russ
                last edited by

                @Russ I would say so.

                It's uninstalled it again for me at some point so I'll need to find a way to trust TriggerCMD.

                RussR 1 Reply Last reply Reply Quote 0
                • RussR Offline
                  Russ @Guest
                  last edited by

                  @Lewis-S, I see a "Apply always" option on your screenshot. That might prevent it from deleting the .exe. You could also exclude that folder from scans.

                  Russell VanderMey

                  1 Reply Last reply Reply Quote 0

                  Hello! It looks like you're interested in this conversation, but you don't have an account yet.

                  Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

                  With your input, this post could be even better 💗

                  Register Login
                  • First post
                    Last post