Link to home
Start Free TrialLog in
Avatar of jeff Lee
jeff Lee

asked on

Windows Defender Antivirus for Windows server 2016 show Behavior:Win32/DefenseEvasion.WI!ml

Hi,
I use delphi 7 to develop AP system in windows sever 2016.
THe Windows Defender scan the exe file and show the following warning-
Behavior:Win32/DefenseEvasion.WI!ml.

Even I use Windows Defender Antivirus for Windows server 2016 to run a full scan and remove this threat,
when I complie the exe AP again and the Windows Defender Antivirus still show Behavior:Win32/DefenseEvasion.WI!ml.

So,what can I do ?

Thanks.
Avatar of Adam Leinss
Adam Leinss
Flag of United States of America image

Submit the file as a false positive to Microsoft: https://www.microsoft.com/en-us/wdsi/filesubmission
It's happened at least twice with the Cherwell cloud installer at my employer.  Microsoft is usually pretty quick on releasing a new definition file fix.

Avatar of jeff Lee
jeff Lee

ASKER

Hi Adam Leinss,
   Thanks for your quick response. I am worried about the issue all of the time.

  Thanks.

jeff 
Iti s a false positive. Exclude that folder and as mentioned above: submit the file to Microsoft as a false positive
ASKER CERTIFIED SOLUTION
Avatar of Sinisa Vuk
Sinisa Vuk
Flag of Croatia image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Hi Sinisa Vuk,
   That's what I worry about.  When I compile the same project,the Windows Defender Antivirus  will show Behavior:Win32/DefenseEvasion.WI!ml, but scan other AP and Windows Defender Antivirus  never show virus message in Delphi.It's so strange.

   I try to use other virus scanner and removal tool to scan and clean  all of the AP, the other virus scanner show all of the AP is clean. ️ How do I know I can trust a virus scanner?

   Thanks.

jeff

Hi David Johnson,
  I had uploaded the AP to Microsoft: https://www.microsoft.com/en-us/wdsi/filesubmission to check  if the AP is Malware or not.

  Thank you for your suggestion.

jeff
Hi Sinisa Vuk,
   Finally, I'd like to thank you for your suggestion. When I remove some third-party components, virus scanner don't show any error message.

  Thanks again.

jeff