{"id":15361,"date":"2020-08-14T15:05:36","date_gmt":"2020-08-14T13:05:36","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=15361"},"modified":"2020-08-14T15:10:44","modified_gmt":"2020-08-14T13:10:44","slug":"microsoft-defender-blockiert-citrix-dienste-als-trojaner","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2020\/08\/14\/microsoft-defender-blockiert-citrix-dienste-als-trojaner\/","title":{"rendered":"Microsoft Defender blocks Citrix services as Trojan"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2015\/01\/Schutz.jpg\" width=\"40\" align=\"left\" height=\"47\">[<a href=\"https:\/\/www.borncity.com\/blog\/2020\/08\/14\/microsoft-defender-blockiert-citrix-dienste-als-trojaner\/\" target=\"_blank\" rel=\"noopener noreferrer\">German<\/a>]Currently, there is a problem that Microsoft Defender detects Citrix services as Trojans after an update and deactivates these services. But there is a workaround, which is described in a support article.<\/p>\n<p><!--more--><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" src=\"https:\/\/vg08.met.vgwort.de\/na\/03cb96ee43dc4417a74bd74f20000327\" width=\"1\" height=\"1\">German blog reader Toni has informed me about this problem by e-mail, which is mentioned in <a href=\"https:\/\/support.citrix.com\/article\/CTX279897\" target=\"_blank\" rel=\"noopener noreferrer\">this KB-post<\/a>, among other things at Citrix. A reddit user <a href=\"https:\/\/www.reddit.com\/r\/sysadmin\/comments\/i9fu71\/microsoft_windows_defender_is_detecting_citrix\/\" target=\"_blank\" rel=\"noopener noreferrer\">describes<\/a> the whole thing like this:&nbsp; <\/p>\n<blockquote>\n<p>Microsoft Windows Defender Is Detecting Citrix Broker Service And Citrix High Availability Service As Trojan<\/p>\n<p>Got issue with customers Citrix services. Spent some time troubleshooting, and found that Citrix Broker service was not there.  <\/p>\n<p>Only when we called up Citrix, then we were told about this issue&#8230; wasted the morning.<\/p>\n<\/blockquote>\n<p>This issue occurs because Windows Defender incorrectly identifies and quarantines the primary and secondary Citrix broker services (BrokerService.exe and HighAvailabilityService.exe) that are responsible for tracking current user connections\/ sessions as Trojans. Well, with such a virus hunter like Microsoft Defender, there is no need for any more malware so that nothing works. Citrix writes about this in <a href=\"https:\/\/support.citrix.com\/article\/CTX279897\" target=\"_blank\" rel=\"noopener noreferrer\">this support article<\/a> from August 14, 2020:&nbsp; <\/p>\n<blockquote>\n<p>Virtual Apps and Desktop: Microsoft Windows Defender Is Detecting Citrix Broker Service And Citrix High Availability Service As Trojan<\/p>\n<h4>Symptoms or Error<\/h4>\n<ul>\n<li>You notice that Citrix Broker service is not present in Services console.&nbsp;\n<li>BrokerService.exe is also missing from c:\\program files\\Citrix\\Broker\\Services\\\n<li>The issue is seen with multiple Windows Defender Versions<br \/>installed on Delivery Controllers.&nbsp;\n<li>Citrix Studio states &#8211; enter the delivery controller address with Error \"Could not contact the Broker Service.\"<\/li>\n<\/ul>\n<\/blockquote>\n<p>Citrix is therefore aware of a potential problem that could affect the Citrix Broker and Citrix High Availability services on the Delivery Controllers and Citrix Cloud Connectors, respectively, with Microsoft Defender installed. <\/p>\n<h2>Workaround: Exclude Citrix services from the scan<\/h2>\n<p>Citirix describes in <a href=\"https:\/\/docs.citrix.com\/en-us\/tech-zone\/build\/tech-papers\/antivirus-best-practices.html\" target=\"_blank\" rel=\"noopener noreferrer\">this article<\/a> best practices for configuring Microsoft Defender to exclude Citrix services from a scan. The following figure shows the affected files:<\/p>\n<p><img decoding=\"async\" title=\"Citrix-Ausnahmen im Defender\" alt=\"Citrix-Ausnahmen im Defender\" src=\"https:\/\/support.citrix.com\/files\/public\/support\/article\/CTX279897\/images\/0EM0z000000ijoM.png\"><br \/>(Citrix Exceptions in Defender, Source: Citrix)<\/p>\n<p>Citrix describes in the support article a further workaround for repairing the services and, if necessary, also proposes a downgrade of the Defender &#8211; which is no longer necessary, however. <\/p>\n<h3>Updating the Defender<\/h3>\n<p>Microsoft is reported to have released an update to Defender (Antivirus Definition 1.321.1341.0) that is intended to resolve the problem. To force the update, open an administrative prompt. Then run the following commands:<\/p>\n<p>cd %ProgramFiles%\\Windows Defender<br \/>MpCmdRun.exe -removedefinitions -dynamicsignatures<br \/>MpCmdRun.exe -SignatureUpdate  <\/p>\n<p>Could also be executed as a batch file with administrator rights. The commands force the deletion of the incorrect signatures and a signature update. Afterwards it should run again. Any of you affected??<\/p>\n<p><strong>Similar articles:<br \/><\/strong><\/p>\n<p><a href=\"https:\/\/borncity.com\/win\/2020\/07\/30\/windows-defender-markiert-ccleaner-als-pup-teil-1\/\">Windows Defender flags CCleaner as PUP \u2013 Part 1<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2020\/08\/03\/windows-defender-lscht-windows-hosts-datei-teil-2\/\">Defender flags Windows Hosts file as malicious \u2013 Part 2<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2020\/08\/04\/defender-blocks-redirected-microsoft-hosts-entries-part-3\/\">Defender blocks redirected Microsoft hosts entries \u2013 Part 3<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2020\/04\/11\/defender-stufte-flschlich-winaero-tweaker-als-hacker-tool-ein\/\">Defender mis-classified Winaero Tweaker as a hacker tool<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2020\/03\/27\/issues-with-defender-update-kb4052623-march-2020\/\">Issues with Defender Update KB4052623 (March 2020)?<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]Currently, there is a problem that Microsoft Defender detects Citrix services as Trojans after an update and deactivates these services. But there is a workaround, which is described in a support article.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[463,580],"tags":[2222,773,47],"class_list":["post-15361","post","type-post","status-publish","format-standard","hentry","category-issue","category-security","tag-citrix","tag-defender","tag-issue"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/15361","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=15361"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/15361\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=15361"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=15361"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=15361"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}