> Source: [sk131312](https://support.checkpoint.com/results/sk/sk131312)

# sk131312 - Endpoint Security Anti-Malware Blade detects DameWare software as malicious

| Property | Value |
|----------|-------|
| Solution ID | sk131312 |
| Date Created | 2018-07-08 |
| Last Modified | 2022-06-11 |
| Technical Level | Advanced |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X |

## Symptoms

- * Endpoint Security Anti-Malware Blade detects DameWare software as malicious.

* Detected files are removed with the following detection name:

  ```
  
  not-a-virus:HEUR:RemoteAdmin.Win32.DameWare.gen
  not-a-virus:RemoteAdmin.Win32.DameWare.d
  not-a-virus:HEUR:RemoteAdmin.MSIL.DameWare.gen
  not-a-virus:VHO:RemoteAdmin.Win32.Convagent.gen
  ```

## Cause

Detection is correct, this software belongs to RemoteAdmin class and this is being detected.

Despite being legitimate software, it is still can be used by malicious actors in some cases to get access to user's system.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
