New
#1
Trojan:Script/Cloxer.D!cl
In the past few days, I restored the same Macrium backup twice. Shortly after I got a Windows Defender alert.
Attachment 235834
Attachment 235835
I didn't take any immediate action, but it seems Windows Defender did it for me.
The results point to Hwmonitor, from the CPUID website. It's portable, and doesn't run in the background. Window Defender only removed its shortcut that was pinned to the start menu. I just ran a Defender scan, and it is clean, now that the shortcut is gone.
I've had the same version of Hwmonitor since September of 2018, with no problem.
Also, it coincidentally happened after I logged into the MightyText desktop app. I don't know if there a connection there or not, but it happened twice.
I couldn't find any real information about the origin of Trojan:Script/Cloxer.D!cl. Could this be a false positive?
What does it mean by "affected items"? And it refers to one of the "affected items" as "startup", but they are both the same item. What's that about?
I went to the quarantine location, and clicked "Learn More". It took me here.
Trojan:Script/Cloxer.D!cl threat description - Microsoft Security Intelligence
The page was updated Sep 24, 2018. Just few days after i got Hwmonitor. Another coincidence?
thanks