What is this odd security warning?

Page 1 of 3 123 LastLast

  1. Posts : 7,905
    Windows 11 Pro 64 bit
       #1

    What is this odd security warning?


    I started getting odd warnings like the one posted below from Defender on my desktop PC and shortcuts being deleted. I then recovered a Reflect backup from 23 Dec well before this started happening today but started getting the warning posted below and shortcuts deleted again. I'm mystified what this is due and how to recover.

    What is this odd security warning?-capture.jpg

    Update - To save you reading the rest of this thread, this issue and deleted shortcuts on the taskbar, desktop (including nested folders) and the start menu are due to a spectacular cockup by Microsoft on Friday 13th. A bad Defender signature (1.381.2140.0) released yesterday (now pulled) caused the ASR rule (Rule ID: 92e97fa1-2edf-4476-bdd6-9dd0b4dddc7b) to misbehave and trigger against users' app shortcuts, falsely tagging them as malicious. The deleted shortcuts will need to be reinstated manually or you can recover from a recent backup.

    Microsoft advise This issue is resolved in security intelligence update build 1.381.2164.0. Installing security intelligence update build 1.381.2164.0 or later should prevent the issue, but it will not restore previously deleted shortcuts

    I'm going to recover from a recent Reflect backup and disconnect from the internet whilst I restore Defender settings to default using Config Defender where I had set some aggressive ASR rules.

    So much for Microsoft's QA
    Last edited by Steve C; 14 Jan 2023 at 03:38.
      My Computers


  2. Posts : 18,044
    Win 10 Pro 64-bit v1909 - Build 18363 Custom ISO Install
       #2

    Hello @Steve C,

    Looking at it, it appears that it is an Office program [ Macro ] that is involved ?
      My Computer


  3. Posts : 7,905
    Windows 11 Pro 64 bit
    Thread Starter
       #3

    I don't have any Office macros. Also a user folder has been removed from my desktop and several icons pinned to the taskbar e.g. Chrome.
      My Computers


  4. Posts : 18,044
    Win 10 Pro 64-bit v1909 - Build 18363 Custom ISO Install
       #4

    Hello @Steve C,

    [1] Have you run ANY Scripts etc prior to this happening ?
    [2] Have you downloaded ANY programs prior to this happening ?
    [3] Have you run a FULL Virus scan or Malwarebytes ?

    I am just on my way out, but I will investigate this further for you when I get back.
      My Computer


  5. Posts : 23,269
    Win 10 Home ♦♦♦19045.4355 (x64) [22H2]
       #5

    @Steve C

    crashpad_handler.exe Windows process - What is it?

    1. First, figure out what it is.
    2. This will help you when Googling, which will lead to further info and if needed, removal techniques.
      My Computer


  6. Posts : 7,905
    Windows 11 Pro 64 bit
    Thread Starter
       #6

    I was perplexed why the odd behaviour reappeared after recovering from backup. I suspect the culprit is a utility called Configure Defender which set some quite aggressive Defender settings. I've now reset those to default and recovered my missing shortcuts on the desktop. Maybe the latest Defender update installed just after recovering from backup didn't play well with those Configure Defender settings? I'll only fiddle with Defender settings from the Windows Settings menu now. There is no sign of any malware.
      My Computers


  7. Posts : 5,048
    Windows 10/11 Pro x64, Various Linux Builds, Networking, Storage, Cybersecurity Specialty.
       #7

    @Steve C -

    Have you tried removing Configure Defender?

    Please download and run this program (no install) and see what it finds, if anything.

    https://www.k7computing.com/us/free_scanner

    Just to be sure.

    Post back with your results.

      My Computer


  8. Posts : 4,803
    Windows 10 preview 64-bit Home
       #8

    Steve C said:
    I was perplexed why the odd behaviour reappeared after recovering from backup. I suspect the culprit is a utility called Configure Defender which set some quite aggressive Defender settings. I've now reset those to default and recovered my missing shortcuts on the desktop. Maybe the latest Defender update installed just after recovering from backup didn't play well with those Configure Defender settings? I'll only fiddle with Defender settings from the Windows Settings menu now. There is no sign of any malware.
    This is what I got,

    What is this odd security warning?-rxncaejui4.png

    Running Windows Subsystem for Android and had Edge running in the background. The old CPU I have on this laptop was struggling a bit so right clicked Edge icon on taskbar to close it. Like you no Office at all and once I closed WSA some desktop icons missing, Edge icon on taskbar had no file associated and Edge missing in all apps list in Windows 11. Had to repair Edge twice to get it running normally.
    Nothing found in Defender after following scan.
      My Computers


  9. Posts : 164
    Win 10 Pro 64b 22H2
       #9
      My Computer


  10. Posts : 4,803
    Windows 10 preview 64-bit Home
       #10

    Thank you, nice find
      My Computers


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 23:41.
Find Us




Windows 10 Forums