Page 1 of 1

Windows Defender

PostPosted: Wed Oct 18, 2023 8:40 am
by Natter
Windows Defender has just been updated. As a result, all programs on the FW are automatically deleted.
The antivirus log says Program:Win32/Wacapew.C!ml
Trojan:Win32/Wacatac.B!ml

I, of course, put the deleted files in the exception. However , I would like to understand - is there a problem or not ?

Re: Windows Defender

PostPosted: Wed Oct 18, 2023 9:05 am
by Antonio Linares
Dear Yuri,

What Windows version are you using ? Are you using latest updates ?

How to check the Windows defender version ?

Here it is working fine

Re: Windows Defender

PostPosted: Wed Oct 18, 2023 9:26 am
by Natter
The situation looks like this. On all local computers there is Windows 10 (the latest version),
90% of them have Kaspersky anti-virus installed. The other 10 are running Windows Defender.
Windows Defender is also installed on the Windows 2016 Data Center server.
Problems occurred when copying the file xx.exe from the local computer to the server -
Defender immediately deleted this file. There were similar problems on local computers with Windows Defender

Re: Windows Defender

PostPosted: Wed Oct 18, 2023 9:54 am
by Antonio Linares
Have you tried to compress the EXE using upx or similar ?

This may help

Re: Windows Defender

PostPosted: Wed Oct 18, 2023 10:27 am
by Natter
I didn't do anything with the file. Everything happened within 1-2 minutes. The
server log says Windows Defender update. I was told that it was the latest version that started deleting files from Program:Win32/Wacapew.C!ml (before that it only warned)

Re: Windows Defender

PostPosted: Wed Oct 18, 2023 10:30 am
by Antonio Linares
If you compress the EXE, the error may go away

Re: Windows Defender

PostPosted: Wed Oct 18, 2023 10:49 am
by Natter
Thanks, I'll try!

Re: Windows Defender

PostPosted: Wed Oct 18, 2023 12:02 pm
by Jack
Hi,
Same problem here in Belgium Windows Defender and Windows 11 .

Re: Windows Defender

PostPosted: Wed Oct 18, 2023 12:40 pm
by karinha

Re: Windows Defender

PostPosted: Wed Oct 18, 2023 2:26 pm
by Enrico Maria Giordano
Try to report the false alarm to Microsoft:

https://www.microsoft.com/en-us/wdsi/filesubmission