Windows 10: False positive threats

Discus and support False positive threats in AntiVirus, Firewalls and System Security to solve the problem; I bought recently a new computer with Windows 11 pre-installed, I made all the necessary updates, installed my applications and finally downloaded... Discussion in 'AntiVirus, Firewalls and System Security' started by Hamdi Zeddini, Dec 11, 2021.

  1. False positive threats


    I bought recently a new computer with Windows 11 pre-installed, I made all the necessary updates, installed my applications and finally downloaded Google drive, by the way I was thinking to switch back to OneDrive but Microsoft didn't as usual fix the damn cloud.Anyway, after getting everything ready, Windows Defender started to find Trojans in my google drive folder, precisely in the temporary folder "C:\Users\don't_have_enough_money_to_buy_mac\My Drive\.tmp.drivedownload", and it keeps warning me about them every time with a lot of notifications, any action I choose allow or remove will no

    :)
     
    Hamdi Zeddini, Dec 11, 2021
    #1
  2. Try3 Win User

    Windows defender false positive - forced to allow threat

    Windows defender has started to identify C:\Windows\System32\mshta.exe as a threat [normally reported as a Trojan Powessere.G]. I use mshta.exe to run an hta custom MsgBox - I have been hoping to keep using my current CustomMsgBox tool [batch file calling a vbs-hta file] until later this year when I hope to have had enough time to replace it with a PowerShell alternative.

    Windows defender's notification lets me "allow the threat" but that seems to me to be a bigger security hole than is necessary - it will now ignore a potentially real intrusion when all I want to run is a genuine Windows component. My immediate problem is fixed but I would prefer to fix the false positive using the exclusions list.

    I cleared the 'Allowed threats history' so I could use the exclusions list instead. I added C:\Windows\System32\mshta.exe to the file exclusions list and I checked that it had taken properly by checking the exclusions list both in the UI & in the Registry. But the exclusion made no difference, it continued to detect and block the exe.

    I have repeated the attempt several times [by clearing the allowed threats list & exclusions list beforehand] and the results are the same every time
    - allowing the threat works,
    - using the exclusions list has no effect.

    I studied the relevant tutorial but have not spotted an error in what I have been doing - Add or Remove Windows Defender Exclusions

    Does anybody with experience of using the exclusions list to counter false positives have any suggestions for me?

    Denis
     
  3. Why does Windows Defender not understand "False Positive"?

    Almost daily now, I've had to clear a "threat" from Defender's "actions needed" list on a specific program that is a false positive.

    How do I make it work as expected?
     
    DreamlessDancer, Dec 11, 2021
    #3
  4. Try3 Win User

    False positive threats

    Windows defender false positive - forced to allow threat

    Thanks, I've noted the link for reference. WD still reports the hta as a trojan [it now calls it kovter.g].

    False positive threats [​IMG]


    I completed development of my PSCustomMsgBox and would not consider going back to the hta version anyway.


    False positive threats [​IMG]


    I can call this from my batch file scripts and from VBA. The caller customises it with the required title, text, number of buttons, button labels, colour scheme, audio announcement & time onscreen.

    Denis
     
Thema:

False positive threats

Loading...
  1. False positive threats - Similar Threads - False positive threats

  2. Is this a false positive?

    in Windows 10 Gaming
    Is this a false positive?: I ran autorun, virustotal says it had trojan virus. Only one steam.exe existed in system.I checked hashes are the same, but I am not sure about sign whether is legit or not.I lived in Thailand, so there must have time zone differenece.The extra 32 seconds compared to the...
  3. Is this a false positive?

    in Windows 10 Software and Apps
    Is this a false positive?: I ran autorun, virustotal says it had trojan virus. Only one steam.exe existed in system.I checked hashes are the same, but I am not sure about sign whether is legit or not.I lived in Thailand, so there must have time zone differenece.The extra 32 seconds compared to the...
  4. False positive??

    in AntiVirus, Firewalls and System Security
    False positive??: Hello! I downloaded a file from web and I think I got viruses or malware from it. First, Windows Defender notified me that I got malware and I deleted all the temp and patched files from my laptop and scanned it after with Microsoft Security Scan and it said I have 0 files...
  5. False positive??

    in Windows 10 Gaming
    False positive??: Hello! I downloaded a file from web and I think I got viruses or malware from it. First, Windows Defender notified me that I got malware and I deleted all the temp and patched files from my laptop and scanned it after with Microsoft Security Scan and it said I have 0 files...
  6. False positive??

    in Windows 10 Software and Apps
    False positive??: Hello! I downloaded a file from web and I think I got viruses or malware from it. First, Windows Defender notified me that I got malware and I deleted all the temp and patched files from my laptop and scanned it after with Microsoft Security Scan and it said I have 0 files...
  7. Is this a false positive

    in Windows 10 Gaming
    Is this a false positive: I'm pretty scared cause I clicked on this link for help and it flagged as malicious https://www.virustotal.com/gui/url/419ed1cdabbd93e665156658d341edf1ef001c4158864fa4ca2ad501839a3dd7?nocache=1...
  8. Is this a false positive

    in Windows 10 Software and Apps
    Is this a false positive: I'm pretty scared cause I clicked on this link for help and it flagged as malicious https://www.virustotal.com/gui/url/419ed1cdabbd93e665156658d341edf1ef001c4158864fa4ca2ad501839a3dd7?nocache=1...
  9. is this a false positive or no?

    in Windows 10 Ask Insider
    is this a false positive or no?: [ATTACH] submitted by /u/GloomyMusician24 [link] [comments] https://www.reddit.com/r/Windows10/comments/lb83rc/is_this_a_false_positive_or_no/
  10. Windows defender false positive - forced to allow threat

    in AntiVirus, Firewalls and System Security
    Windows defender false positive - forced to allow threat: Windows defender has started to identify C:\Windows\System32\mshta.exe as a threat [normally reported as a Trojan Powessere.G]. I use mshta.exe to run an hta custom MsgBox - I have been hoping to keep using my current CustomMsgBox tool [batch file calling a vbs-hta file]...