Anti-malware Incident Alerts
Between 6 May 2026 and 6 July 2026, our Anti-Malware flagged several activation and cracking tools saved on laptop LWINSGPC0PCF6V. These sat in a folder inside the user's Documents area, at "C:\Users\user\Documents\SOFTWARE Don't Delete". They included the KMSAuto activation tool ("KMSAuto.exe", "KMSAuto x64.exe" and "KMSTools.exe"), a Windows license activation script file ("slc.dll"), a general Windows activator ("gAll activation Windows (7-8-10) v8.5.exe"), and a third-party driver installer ("DriverPack-17-Online.exe"). Our Anti-Malware detected each of these, meaning it recorded and flagged them but did not remove them, so they may still be on the laptop.
Tools that unlock software without a proper licence carry real risk, even when nothing bad has happened yet. They often come bundled with hidden extras, and to do their job they change core parts of the system, which can quietly weaken your protections over time. They also fall outside licensing rules, which can be a compliance concern. To be clear, there is no sign of compromise here and nothing was seen causing harm. Even so, it is worth confirming whether this software is approved for business use and removing it if it is not needed.
192.168.1.217
Device name: sean's MacBook Air
Operating system: macOS
IP address: 172.31.52.179
MAC address: a2:33:d0:62:50:1d
Security agent version: PANW/XDR Agent 8.9.0.3620
Alert severity: High
Alert type: Malware
Attack strategy (MITRE tactic): TA0040 - Impact
Attack method (MITRE technique): T1657 - Financial theft
7zFM.exeC:\Program Files\7-Zip\7zFM.exe"C:\Program Files\7-Zip\7zFM.exe" "C:\Users\Sec504\Desktop\beotmv3.zip"7zFM.exeC:\Program Files\7-Zip\7zFM.exe"C:\Program Files\7-Zip\7zFM.exe" "C:\Users\Sec504\Desktop\beotmv3.zip"