Windows 10: Allowed threats in Defender that i never added?

Discus and support Allowed threats in Defender that i never added? in Windows 10 Ask Insider to solve the problem; When I opened "allowed threats" in microsoft defender, a bunch of trojans appeared. I do not download anything sketchy online and manually allow them... Discussion in 'Windows 10 Ask Insider' started by /u/terr_terrible, May 30, 2022.

  1. Allowed threats in Defender that i never added?


    When I opened "allowed threats" in microsoft defender, a bunch of trojans appeared. I do not download anything sketchy online and manually allow them on defender, what could possibly explain this? Are these false positives?

    Ex. Trojan:win32/ludicrouz.Z Trojan:win32/conteban.B!ml Trojan:win32/defenseevasion!rfn

    submitted by /u/terr_terrible
    [link] [comments]

    :)
     
    /u/terr_terrible, May 30, 2022
    #1
  2. Try3 Win User

    Windows defender false positive - forced to allow threat

    Windows defender has started to identify C:\Windows\System32\mshta.exe as a threat [normally reported as a Trojan Powessere.G]. I use mshta.exe to run an hta custom MsgBox - I have been hoping to keep using my current CustomMsgBox tool [batch file calling a vbs-hta file] until later this year when I hope to have had enough time to replace it with a PowerShell alternative.

    Windows defender's notification lets me "allow the threat" but that seems to me to be a bigger security hole than is necessary - it will now ignore a potentially real intrusion when all I want to run is a genuine Windows component. My immediate problem is fixed but I would prefer to fix the false positive using the exclusions list.

    I cleared the 'Allowed threats history' so I could use the exclusions list instead. I added C:\Windows\System32\mshta.exe to the file exclusions list and I checked that it had taken properly by checking the exclusions list both in the UI & in the Registry. But the exclusion made no difference, it continued to detect and block the exe.

    I have repeated the attempt several times [by clearing the allowed threats list & exclusions list beforehand] and the results are the same every time
    - allowing the threat works,
    - using the exclusions list has no effect.

    I studied the relevant tutorial but have not spotted an error in what I have been doing - Add or Remove Windows Defender Exclusions

    Does anybody with experience of using the exclusions list to counter false positives have any suggestions for me?

    Denis
     
  3. zebal Win User
    Windows Defender/Security - no option to "Allow" potential threats?

    If you want to control what does defender do to threats you can do it trough GPO in the following location:

    Computer configuration\Administrative templates\Windows components\Microsoft defender antivirus\Threats
    Here configure option:
    Specify threats upon which default action should not be taken when detected

    Threats are categorized by level, you assign default action per threat level.

    EDIT:
    Btw. to open GPO (Local Group Policy) follow these steps:

    1. click on start button
    2. type: gpedit.msc
    3. right click on gpedit.msc and run as Administrator
     
    zebal, May 30, 2022
    #3
  4. gagagaON Win User

    Allowed threats in Defender that i never added?

    Is restoring a quarantined threat the same as allowing the threat?

    My Windows defender scan reported a threat last week. I quarantined it. After a few days, I updated my defender virus definitions, restored the threat, and ran another scan (because I wanted to find out if it was a false positive). This new scan did not
    report any threat.

    However, under defender's threat history, allowed items, I see this threat listed. I do NOT want to allow the threat, just wanted to find out if the latest definitions would still reported the file as a threat. How should I do that? Thank you. I am using
    windows 10.
     
    gagagaON, May 30, 2022
    #4
Thema:

Allowed threats in Defender that i never added?

Loading...
  1. Allowed threats in Defender that i never added? - Similar Threads - Allowed threats Defender

  2. Defender Keeps Reporting Allowed Threats

    in Windows 10 Gaming
    Defender Keeps Reporting Allowed Threats: I've looked for answers to this but am not finding them. Windows Defender recently started detecting a utility we use at work written by one of my coworkers in AutoIT as malware. While we've made allowance for it through MDE, Defender on my home computer is also reporting it...
  3. Defender Keeps Reporting Allowed Threats

    in AntiVirus, Firewalls and System Security
    Defender Keeps Reporting Allowed Threats: I've looked for answers to this but am not finding them. Windows Defender recently started detecting a utility we use at work written by one of my coworkers in AutoIT as malware. While we've made allowance for it through MDE, Defender on my home computer is also reporting it...
  4. Defender Keeps Reporting Allowed Threats

    in Windows 10 Software and Apps
    Defender Keeps Reporting Allowed Threats: I've looked for answers to this but am not finding them. Windows Defender recently started detecting a utility we use at work written by one of my coworkers in AutoIT as malware. While we've made allowance for it through MDE, Defender on my home computer is also reporting it...
  5. Virus automatically gets added to allowed threats of windows defender, and so are not removed.

    in AntiVirus, Firewalls and System Security
    Virus automatically gets added to allowed threats of windows defender, and so are not removed.: Few viruses gets added to the allowed threats category of windows defender automatically. Even if I manually remove them, they get added back immediately afterwards. I have tried running full scan and offline scan from scan options but they did not help either. I do not like...
  6. Can't remove allowed threats from window defender

    in AntiVirus, Firewalls and System Security
    Can't remove allowed threats from window defender: Hello, I'm trying to delete allowed threats from windows defender. I don't remember when I allowed them, but I can't remove them because when I click Don't allow and then refresh the page, I see them repeatedly. I also tried to make f full scan, but it shows nothing.What I...
  7. impossible remove threat from windows defender "allowed threats"

    in AntiVirus, Firewalls and System Security
    impossible remove threat from windows defender "allowed threats": Windows defender notify me threat, but when i try to remove, the threat was moved in permitted threats and when i try to not allow end remove, uac ask me to proceed but the threat wasn't remove. [ATTACH][ATTACH]...
  8. Windows Defender and Trojan in "Allowed threat"

    in AntiVirus, Firewalls and System Security
    Windows Defender and Trojan in "Allowed threat": Hi guys, I have problem, I have Trojan and behavior in allowed threats. When I click remove and again open allowed threats, vrius still is in there. What I should to do ? Is it Windows defender bug or I still have a virus ? Btw I used malwarebytes and windows defender...
  9. windows defender allowed threat isn't saved

    in AntiVirus, Firewalls and System Security
    windows defender allowed threat isn't saved: I allowed a threat through windows defender but It eventually gets removed from allowed threats and reappear waiting for me to take actions. I don't intend to exclude it because it won't get detected even if it got infected with other malware. I only want to allow this...
  10. Windows Defender and Allowed Threats

    in AntiVirus, Firewalls and System Security
    Windows Defender and Allowed Threats: So the issue that I am having is that I have some stuff running on my my PC that technically is a virus but it has a specific purpose and I want it to run. I repeatedly have to restore the files and allow them. It happens at least 2-3 times a week....