Actions Required After Verifying False Positives in Windows Defender

김 청 0 Reputation points
2024-10-08T05:38:48.8133333+00:00

A customer support inquiry was received regarding our game executable (.exe) being detected as Trojan/Wacatac.B!ml. Several posts on our game site’s community have reported similar issues.

The file in question is a program built and distributed by our company and is installed via the launcher that we also distribute. This software has been in service for 19 years and includes a digitally signed official certification, leading us to believe the detection is a false positive. We submitted the file for verification through https://www.microsoft.com/en-us/wdsi. We requested a review for both Trojan/Wacatac.B!ml and PUA/Puwaders.C!ml detections. However, only the detection for Trojan/Wacatac.B!ml was removed.

We have the following questions:

  • Since our game executable is updated with each new version, will continuous file verification requests be necessary?
  • For users affected by this issue, does Windows Defender require an additional patch? If so, could guidance on the patching process be provided? Our users tend to be older, so a simple and straightforward solution is requested.
  • If the executable has already been quarantined due to the false positive, will it be restored?

Thank you.

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
213 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Prathista Ilango 95 Reputation points Microsoft Employee
    2024-11-07T09:41:02.9933333+00:00

    Please find below the answers to your queries,

    • Since our game executable is updated with each new version, will continuous file verification requests be necessary?

    Yes. It recommended to submit for verification if there is any new update on the exe.

    Submit files for analysis by Microsoft - Microsoft Defender XDR | Microsoft Learn

    Also please refer to Software developer FAQ - Microsoft Defender XDR | Microsoft Learn and How Microsoft identifies malware and potentially unwanted applications - Microsoft Defender XDR | Microsoft Learn while developing your application. Keeping these criteria in mind while developing applications could help avoid false positives. 

     

    • For users affected by this issue, does Windows Defender require an additional patch? If so, could guidance on the patching process be provided? Our users tend to be older, so a simple and straightforward solution is requested.

    Windows Defender doesn't require any additional patching. The definition updates that happen regularly will be sufficient.  It also depends on how the automatic patching is configured for your org. If no software update management is in place, just ensure your device and defender are up to date.

    Update Windows - Microsoft Support 

    Virus & threat protection in Windows Security - Microsoft Support -

    On the Virus & threat protection page, under Virus & threat protection updates, select Check for updates to scan for the latest security intelligence.

     

     Please note system updates require reboot, but defender definitions don't require reboot.

     

    •  If the executable has already been quarantined due to the false positive, will it be restored?

    You can manually restore it. If the file is determined to be safe after Microsoft's investigation, it won't detect further unless the file changes (this is the reason to submit for verification when there is an updated version). Alternatively, if you are sure, it is a false positive, you can add an exclusion in place to avoid this detection in future.

    Restore quarantined files in Microsoft Defender Antivirus - Microsoft Defender for Endpoint | Microsoft Learn

    Add an exclusion to Windows Security - Microsoft Support

     

    If you found the information above helpful, please Accept the answer. This will assist others in the community who encounter a similar issue, enabling them to quickly find the solution and benefit from the guidance provided.

    0 comments No comments

  2. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.