Windows 10: Defender Found Trojan in USMT.ppkg - real or false positive?

Discus and support Defender Found Trojan in USMT.ppkg - real or false positive? in AntiVirus, Firewalls and System Security to solve the problem; I recently bought an MSI Raider GE431. I ran a full anti-virus scan using Windows Defender. It found the following: Trojan:Win32/Generic!rfn... Discussion in 'AntiVirus, Firewalls and System Security' started by Fleapower, Apr 6, 2020.

  1. Fleapower Win User

    Defender Found Trojan in USMT.ppkg - real or false positive?


    I recently bought an MSI Raider GE431. I ran a full anti-virus scan using Windows Defender. It found the following:



    Trojan:Win32/Generic!rfn

    Affected items:

    containerfile: C:\Recovery\Customizations\USMT.ppkg

    file: C:\Recovery\Customizations\USMT.ppkg->\ICB\0\MachineSpecific\File\C$\Program Files x86\InstallShield Installation Information\{C65B26BC-5A6F-4135-9678-55A877655471}\setup.exe00



    More info is found on Microsoft's site. I've tried to quarantine the file, but Windows Defender is unable to do so. This is a brand new laptop so I tend to think it's a false positive.



    I've done a search and found a handful of related articles, but nothing definitive. Does anyone have any additional information or suggestions about how to proceed?



    Thanks!

    :)
     
    Fleapower, Apr 6, 2020
    #1

  2. database of malware producing false positives or false negatives

    Many months ago I communicated with Malwarebytes about a trojan that was detected by Defender that was not detected by Malwarebytes. They indicated that Microsoft Defender is likely a false positive and to wait weeks or months for Microsoft to update their
    database. To date the Defender continues to detect a trojan that is not detected by Malwarebytes.

    Defender does not detect any malware on quick scans. However on full scans it detects this trojan that is not detected by Malwarebytes.

    How does an end user determine whether one antivirus program is producing false positives or false negatives?
     
    questions_, Apr 6, 2020
    #2
  3. JDLinn Win User
    False Positive - Rundas!plick Trojan

    We have a small "exe" that we use extensively at "Return to Misty Moorings" This is for our "Season Switcher". When the program is run, the software is quarantined as a Rundas!plick Trojan. There is no Trojan or any other problem with this software, Malwarebytes
    and Spybot both show it does not have a problem. But every time our users try it with Defender, it is "quarantined". This is giving our site and our efforts for our fans a bad name from Microsoft's false positive. The program can be found at:

    Return to Misty Moorings - NOTAMS

    The "solution" from the Microsoft "help" chat was to "Turn off Windows Defender". That we can do and I can tell my thousands of followers on the site that this is Microsoft's suggestion (not a very good marketing idea). We need someone on the Defenders
    team to get our software "CLEARED" so this does not keep showing up as a Rundas!plick Trojan.

    Please tell us who to contact or what needs to be done next.

    Doug Linn/RTMM
     
    JDLinn, Apr 6, 2020
    #3
  4. Try3 Win User

    Defender Found Trojan in USMT.ppkg - real or false positive?

    Windows defender false positive - forced to allow threat

    Windows defender has started to identify C:\Windows\System32\mshta.exe as a threat [normally reported as a Trojan Powessere.G]. I use mshta.exe to run an hta custom MsgBox - I have been hoping to keep using my current CustomMsgBox tool [batch file calling a vbs-hta file] until later this year when I hope to have had enough time to replace it with a PowerShell alternative.

    Windows defender's notification lets me "allow the threat" but that seems to me to be a bigger security hole than is necessary - it will now ignore a potentially real intrusion when all I want to run is a genuine Windows component. My immediate problem is fixed but I would prefer to fix the false positive using the exclusions list.

    I cleared the 'Allowed threats history' so I could use the exclusions list instead. I added C:\Windows\System32\mshta.exe to the file exclusions list and I checked that it had taken properly by checking the exclusions list both in the UI & in the Registry. But the exclusion made no difference, it continued to detect and block the exe.

    I have repeated the attempt several times [by clearing the allowed threats list & exclusions list beforehand] and the results are the same every time
    - allowing the threat works,
    - using the exclusions list has no effect.

    I studied the relevant tutorial but have not spotted an error in what I have been doing - Add or Remove Windows Defender Exclusions

    Does anybody with experience of using the exclusions list to counter false positives have any suggestions for me?

    Denis
     
    Try3, Apr 6, 2020
    #4
Thema:

Defender Found Trojan in USMT.ppkg - real or false positive?

Loading...
  1. Defender Found Trojan in USMT.ppkg - real or false positive? - Similar Threads - Defender Found Trojan

  2. wacatac.H!ml trojan false positive?

    in Windows 10 Gaming
    wacatac.H!ml trojan false positive?: Hello,I have had a false positive with this file for a few days now.https://builds.enginehub.org/job/worldguard/23827KB2310138 - 1.409.145.0 https://answers.microsoft.com/en-us/windows/forum/all/wacatachml-trojan-false-positive/a6508c5b-4ebd-4624-8bb2-235ccd89ebf5
  3. wacatac.H!ml trojan false positive?

    in Windows 10 Software and Apps
    wacatac.H!ml trojan false positive?: Hello,I have had a false positive with this file for a few days now.https://builds.enginehub.org/job/worldguard/23827KB2310138 - 1.409.145.0 https://answers.microsoft.com/en-us/windows/forum/all/wacatachml-trojan-false-positive/a6508c5b-4ebd-4624-8bb2-235ccd89ebf5
  4. Wacatac trojan horse infection or false positive?

    in Windows 10 Gaming
    Wacatac trojan horse infection or false positive?: Hi,I booted up my computer and immediately recieved a notification that Wacatac was detected by Microsoft security.I ran a scan to remove it, so now its saying no virus is detected but "remediation is incomplete" in protection history.I ran a scan with Malwarebytes and KVRT...
  5. False positive in Defender?

    in AntiVirus, Firewalls and System Security
    False positive in Defender?: Defender has just identified an alleged Script/Wacatc.B1Ml trojan in a zip file that has been on my system for many years. It didn't object to the unzipped version, a vbs file. I don't know where the zip file has been put, to send a sample and I can't remember how to send...
  6. False Positive for Trojan Virus

    in AntiVirus, Firewalls and System Security
    False Positive for Trojan Virus: Can anyone tell me how and where i can submit my website to be re-looked at? Microsoft Defender is blocking my website that was hacked in the past but i have since addressed all those problems and I guess Microsoft Defender is going off of the old information. I need to...
  7. Feedback for Windows Defender false positive found

    in AntiVirus, Firewalls and System Security
    Feedback for Windows Defender false positive found: Hello, where can be send for repair info about false positive found e.g. threat? Thanks. https://answers.microsoft.com/en-us/protect/forum/all/feedback-for-windows-defender-false-positive-found/05fac603-354c-4f88-949d-616cb0051330
  8. False or real Trojan warning

    in AntiVirus, Firewalls and System Security
    False or real Trojan warning: Hi, I have a very strange trojan warning. I have developed a Windows application.exe in C++ with Visual Studio 2019. After I have made the code and it is in the Release folder, I run both a Windows Defender full scan of my PC and also a custom scan of the new...
  9. Sandboxie 5.28 - Trojan or False Positive - Inquiry

    in AntiVirus, Firewalls and System Security
    Sandboxie 5.28 - Trojan or False Positive - Inquiry: According to both Virus Total & OPSWAT, Sandboxie 5.28 contains the Trojan Shelma. See for yourself. Just download Sandboxie 5.28 then upload to the 2 following online scanners. https://www.virustotal.com/#/home/upload https://metadefender.opswat.com/#!/ Informed...
  10. Windows Defender False Positives

    in AntiVirus, Firewalls and System Security
    Windows Defender False Positives: I received an alarming message from WD which says all antivirus providers are disabled, which I think was a false positives. So I went on a check. And the result: [ATTACH] Protection is on, license is active and my firewall is on too. Can you tell why that message is...

Users found this page by searching for:

  1. containerfile: C:\Recovery\Customizations\USMT.ppkg

    ,
  2. trojan:win32/generic!rfn