Anti-malware Incident Alerts

Your Silent Shield At Work — Catching Threats Before They Cause Chaos. This is your central dashboard of all the incidents we detected and automatically blocked behind the scenes, before it could disrupt your business.
Suspicious malware activity blocked, indicating potential ransomware
Created on
16-Nov-2025 2:41AM
Last updated on
26-Nov-2025 5:54PM
Severity
Critical
Closed on
-
Initial Assessment
Investigated by StrongKeep
What happened

Between 6 May 2026 and 6 July 2026, our Anti-Malware flagged several activation and cracking tools saved on laptop LWINSGPC0PCF6V. These sat in a folder inside the user's Documents area, at "C:\Users\user\Documents\SOFTWARE Don't Delete". They included the KMSAuto activation tool ("KMSAuto.exe", "KMSAuto x64.exe" and "KMSTools.exe"), a Windows license activation script file ("slc.dll"), a general Windows activator ("gAll activation Windows (7-8-10) v8.5.exe"), and a third-party driver installer ("DriverPack-17-Online.exe"). Our Anti-Malware detected each of these, meaning it recorded and flagged them but did not remove them, so they may still be on the laptop.

The facts, for the record
What it was
Unlicensed Windows and Office activation tools, including KMSAuto (KMSAuto.exe, KMSAuto x64.exe, KMSTools.exe), a Windows license activation script (slc.dll) and a driver installer (DriverPack-17-Online.exe)
Where
Laptop LWINSGPC0PCF6V, in a folder under the user's Documents (C:\Users\user\Documents\SOFTWARE Don't Delete)
How it was caught
Detected and flagged by our Anti-Malware as unwanted or risky software (may still be on the device)
Detection source
StrongKeep Anti-Malware
Why it matters

Tools that unlock software without a proper licence carry real risk, even when nothing bad has happened yet. They often come bundled with hidden extras, and to do their job they change core parts of the system, which can quietly weaken your protections over time. They also fall outside licensing rules, which can be a compliance concern. To be clear, there is no sign of compromise here and nothing was seen causing harm. Even so, it is worth confirming whether this software is approved for business use and removing it if it is not needed.

Final Assessment
Status
Closed
Description
Security test
Device name
DESKTOP-DSJFNN5
Operating System
Windows 11
Device type
Workstation
Device owner
Michael Brown
IP Address
192.168.60.142
Public IP
42.61.125.186
MAC Address
00:0c:29:c2:ba:79
Agent Version
PANW/XDR Agent 8.8.0.10622
Device name
aikiF-LT-BKMR2
Operating System
Windows 11
Device type
Workstation
Device owner
Greta Montana
IP Address
100.70.122.102
192.168.1.217
Public IP
119.234.186.205
MAC Address
8c:c6:81:97:9c:bc
Agent Version
PANW/XDR Agent 8.8.0.10622
This is a good-housekeeping review rather than an emergency, and here is a simple way to work through it.
1
Check the licence
Check with your IT or software team whether Windows and Office on this laptop are covered by a proper, paid licence, and whether these activation tools are approved for business use.
2
Uninstall the activation tools
If they are not approved or not needed, open the Windows Start menu, type "Add or remove programs", open it, and uninstall any listed activation or driver tools such as KMSAuto or DriverPack.
3
Delete the leftover files
Using File Explorer, go to "C:\Users\user\Documents\SOFTWARE Don't Delete" and delete the leftover files in that folder, including "KMSAuto.exe", "slc.dll" and "DriverPack-17-Online.exe".
4
Speak with the user
Have a kind, no-blame word with the person who uses this laptop to understand why the tools were added, so you can arrange a properly licensed option if they need one.
5
Review software approval
Please review whether this software is approved for business use, and remove it from the affected device(s) if it is not required.
Flagged Files (1)
File name
EDRSilencer.exe
Wildfire verdict
Malware
Signature vendor
Unknown
Signature status
Signature unsigned
Executed as a process?
Yes
SHA256 Hash
ae12d910467afc9392b96cdcfbbe958fc42659a1c289b8dd7f6c33b65c8213e5
Benign Files (3)
File name
7zFM.exe
Wildfire verdict
Benign
Signature vendor
Igor Pavlov
Signature status
Signature valid
File name
powershell.exe
Wildfire verdict
Benign
Signature vendor
Microsoft Windows
Signature status
Signature valid
File name
beotmv3.zip
Wildfire verdict
Benign
Signature vendor
-
Signature status
-
16-Nov-2025 2:41AM
Incident created
Incident detected on DESKTOP-DSJFNN5.
18-Nov-2025 3:10PM
4 alerts detected on Sec504Student
4 alerts observed over multiple instances on DESKTOP-DSJFNN5 between 16-Nov-2025 2:41AM and 18-Nov-2025 3:10PM.
26-Nov-2025 5:54PM
Incident closed
Marked as closed following security test verification.
Alert #109: Suspicious Process Creation
Detected on 18-Nov-2025 3:10PM
Summary
Alert 'Suspicious Process Creation - 426137201' (Medium severity) in category 'Malware' was detected on host Sec504Student by user Sec504 at 18-Nov-2025 3:10PM. The process 'powershell.exe' was launched with an encoded command and was blocked before execution.
Alert #110: Script Engine Activity
Detected on 18-Nov-2025 4:26PM
Summary
Alert 'Script Engine Activity - 426137455' (High severity) in category 'Malware' was detected on host Sec504Student by user Sec504 at 18-Nov-2025 4:26PM. The process 'powershell.exe' attempted to run a script referencing a remote resource and was blocked.
Alert #123: Ransomware Activity
Detected on 18-Nov-2025 4:26PM
Summary
Alert 'Ransomware Activity - 426137677' (High severity) in category 'Malware' was detected on host Sec504Student by user Sec504 at 18-Nov-2025 4:26PM. Causality analysis ties the alert to process '7zFM.exe' at C:\Program Files\7-Zip\7zFM.exe using command '"C:\Program Files\7-Zip\7zFM.exe" "C:\Users\Sec504\Desktop\beotmv3.zip"' executed at 18-Nov-2025 11:41PM (Unsigned). The process '7zFM.exe' ran with command '"C:\Program Files\7-Zip\7zFM.exe" "C:\Users\Sec504\Desktop\beotmv3.zip"' and was blocked.
Device information:

Device name: sean's MacBook Air

Operating system: macOS

IP address: 172.31.52.179

MAC address: a2:33:d0:62:50:1d

Security agent version: PANW/XDR Agent 8.9.0.3620

Technical details

Alert severity: High

Alert type: Malware

Attack strategy (MITRE tactic): TA0040 - Impact

Attack method (MITRE technique): T1657 - Financial theft

Advanced details
Actor Process Involved
Program name: 7zFM.exe
Program location: C:\Program Files\7-Zip\7zFM.exe
Command executed: "C:\Program Files\7-Zip\7zFM.exe" "C:\Users\Sec504\Desktop\beotmv3.zip"
Verification status: Unsigned
Root Cause
Program name: 7zFM.exe
Program location: C:\Program Files\7-Zip\7zFM.exe
Command executed: "C:\Program Files\7-Zip\7zFM.exe" "C:\Users\Sec504\Desktop\beotmv3.zip"
Verification status: Unsigned
Alert #124: Ransomware Activity
Detected on 18-Nov-2025 4:26PM
Summary
Alert 'Ransomware Activity - 426137678' (High severity) in category 'Malware' was detected on host Sec504Student by user Sec504 at 18-Nov-2025 4:26PM. A second, related instance of the same process behaviour was blocked on retry.