Skip to main content

severe threat is windows defender ! What !

severe threat is windows defender ! What !



I dont get it is this false positive?


I actually scanned with malwarebytes and found nothing yesterday

I dont get it is this false positive?
Personally I would select the Remove all option, as it looks positive to me. This isnt the Windows Defender application itself, as thats located in C:Program FilesWindows Defender.

At a guess, I think the bottom location (FilesStash) is probably the location where Windows Defender is storing the file that it has quarantined.

The top location (LocalCopy) is where Microsoft has made its own copy of the suspicious file, in order to prepare and send a copy of the file to Microsoft for sample submission and evaluate the file.

When Ive had Windows Defender ask to send a sample file submission to Microsoft before, it makes its own copy of the suspicious file. It then sends the files listed below to watson.telemetry.microsoft.com.nsatc.net, which ties in with the location in your screenshot:

?C:ProgramDataMicrosoftWindows DefenderLocalCopy{Identifier Number}-Filename.exe
C:UsersUSERAppDataLocalTempMPSampleSubmitclient_manifest.xml
C:UsersUSERAppDataLocalTempWER1C6.tmp.WERInternalMetadata.xml

You can read about the file that has been quarantined by Windows Defender here:
Trojan:Win32/Spursint.A!cl

yeah i removed it

severe threat is windows defender?! What?!


go to link download

Popular posts from this blog

DroidJack RAT Androrat Android Sample

Modern Combat 2 Black Pegasus apk data Free Download

Notepad 6 6 8