TRIGGERcmd
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Groups
    • Search
    • Register
    • Login

    Kaspersky Detects TriggerCMDAgent.exe as Win32.BSS.ScreenLock

    General Discussion
    2
    7
    354
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • ?
      A Former User
      last edited by

      Hello, I'm using Kaspersky Total Security, and it's deleted c:\users\xxx\appdata\local\triggercmdagent\app-1.0.22\triggercmdagent.exe as Win32.BSS.ScreenLock and deleted it.

      Any insight?

      Thank you

      RussR 1 Reply Last reply Reply Quote 0
      • RussR
        Russ @A Former User
        last edited by Russ

        @Lewis-S, it's a false positive unless the exe has been manipulated. If you have another PC with TRIGGERcmd you could copy the exe from it and do a file compare with the fc command. That assumes Kapersky moved it to quarantine rather than deleting it.

        If you confirm it's the same, you can exclude it from scanning, and ideally report the false positive to Kapersky.

        Later today I'll see if I can get a copy of Kapersky to try a scan.

        Russell VanderMey

        1 Reply Last reply Reply Quote 0
        • ?
          A Former User
          last edited by

          I'll redownload it and see if It redetects if i scan it.

          I'll report as false positive.

          Thanks!

          1 Reply Last reply Reply Quote 0
          • ?
            A Former User
            last edited by A Former User

            hey @Russ ,
            It's having a right fit about TriggerCMD making TCP connections, and running Command Host processes!

            I've allowed it to do all these, there was lots of these boxes to allow!
            9d2fcd97-9b7d-4e0b-a072-91404e49e7c1-image.png

            I'm unsure why only now it decides that TriggerCMD is not okay!

            RussR 1 Reply Last reply Reply Quote 0
            • RussR
              Russ @A Former User
              last edited by Russ

              @Lewis-S, I don't know. Maybe Kaspersky has heuristics that noticed the agent running commands it thought were suspicious. Not necessarily on your computer, but it ended up in their database as a suspicious exe. Just a theory.

              Russell VanderMey

              ? 1 Reply Last reply Reply Quote 0
              • ?
                A Former User @Russ
                last edited by

                @Russ I would say so.

                It's uninstalled it again for me at some point so I'll need to find a way to trust TriggerCMD.

                RussR 1 Reply Last reply Reply Quote 0
                • RussR
                  Russ @A Former User
                  last edited by

                  @Lewis-S, I see a "Apply always" option on your screenshot. That might prevent it from deleting the .exe. You could also exclude that folder from scans.

                  Russell VanderMey

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post