So I recently bought bitdefender total, after doing a custom scan that targeted all the drives on my laptop. Bitdefender detected this "Generic.Application.HackTool.KMS.A.DD98CF7E", the file was located in "C:\Windows\Setup\SCRIPTS\HWID_Activation_AIO.cmd". After the scan was completed I clicked on "take appropriate action" and bitdefender deleted the file. It then declared my laptop safe. Out of curiosity, I visited the file and found 2 other.cmds named: KMS_VL_ALL_AIO.cmd and SetupComplete.cmd. I put both into virustotal and the KMS one came back with 10 hits from various AVs. The setupcomplete one came back clean. Also i didn't click and run them at all other than drag and drop them on virustotal.
heres the VT link for the KMS cmd and setupcomplete.
https://www.virustotal.com/gui/file/e4834aaf04092bbd62048c9182a9d92fd527f900c72666d1e9f2dabbc6dddd03
https://www.virustotal.com/gui/file/e6350ebb89ad2455c29cd16ca529cf8f2b8ca40ec7598fab5abc27ac472fef52
I did some research and the internet says it a malicious trojan that acts as back door for more malicious things (I'm no expert so correct me if im wrong). Normally when the results from virus total contain a few hits from lesser known AVs im not so worried but in this case Kaspersky and ESET-NOD32 flagged it as malicious. That got me worried, why hasn't bitdefender detected it. I have a legit copy of windows and that goes for all programs on my laptop. I have no memory of visiting any dodgy websites or downloading anything dodgy. This has got me worried, is it a false positive or should I take other measures? Anyhelp is greatly appreciated.