> Source: [sk180747](https://support.checkpoint.com/results/sk/sk180747)

# sk180747 - False positive detection of internal file "inject.exe"

| Property | Value |
|----------|-------|
| Solution ID | sk180747 |
| Date Created | 2023-03-20 |
| Last Modified | 2023-04-19 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |
| Platform | TE |

## Symptoms

- *inject.exe* is detected as "riskware" by Kaspersky Anti-Virus and Check Point's Endpoint when scanning *te_image_prep.iso*.

## Cause

`inject.exe` is an internal file located in the Threat Emulation package of Image Prepare ISO - `te_image_prep.iso`. The file is a part of the sandbox, and it is used to inject an internal DLL into existing processes inside the VMs of Threat Emulation to monitor their behavior.

## Solution

This is a false positive, `inject.exe` is an internal file used by Threat Emulation.  
If you use Endpoint, add an exception to the file.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
