severe threat is windows defender?! What?!


  1. Posts : 90
    Microsoft Windows 10 Pro N 64-bit 10240 Multiprocessor Free
       #1

    severe threat is windows defender?! What?!


    I dont get it is this false positive?

    severe threat is windows defender?! What?!-capture.png
      My Computer


  2. Posts : 90
    Microsoft Windows 10 Pro N 64-bit 10240 Multiprocessor Free
    Thread Starter
       #2

    I actually scanned with malwarebytes and found nothing yesterday
      My Computer


  3. Posts : 487
       #3

    Cromax said:
    I dont get it is this false positive?
    Personally I would select the 'Remove all' option, as it looks positive to me. This isn't the Windows Defender application itself, as that's located in C:\Program Files\Windows Defender\.

    At a guess, I think the bottom location (FilesStash) is probably the location where Windows Defender is storing the file that it has quarantined.

    The top location (LocalCopy) is where Microsoft has made it's own copy of the suspicious file, in order to prepare and send a copy of the file to Microsoft for sample submission and evaluate the file.

    When I've had Windows Defender ask to send a sample file submission to Microsoft before, it makes it's own copy of the suspicious file. It then sends the files listed below to watson.telemetry.microsoft.com.nsatc.net, which ties in with the location in your screenshot:

    \\?\C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{Identifier Number}-Filename.exe
    C:\Users\USER\AppData\Local\Temp\MPSampleSubmit\client_manifest.xml
    C:\Users\USER\AppData\Local\Temp\WER1C6.tmp.WERInternalMetadata.xml

    You can read about the file that has been quarantined by Windows Defender here:
    Trojan:Win32/Spursint.A!cl
      My Computer


  4. Posts : 90
    Microsoft Windows 10 Pro N 64-bit 10240 Multiprocessor Free
    Thread Starter
       #4

    yeah i removed it
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 00:17.
Find Us




Windows 10 Forums