{"id":24152,"date":"2022-04-21T01:09:32","date_gmt":"2022-04-20T23:09:32","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=24152"},"modified":"2022-04-21T01:16:22","modified_gmt":"2022-04-20T23:16:22","slug":"microsofts-defender-bemkelt-google-chrome-updates-als-malware-april-2022","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2022\/04\/21\/microsofts-defender-bemkelt-google-chrome-updates-als-malware-april-2022\/","title":{"rendered":"Microsofts Defender flags Google Chrome Updates falsely as malicious (April 20, 2022)"},"content":{"rendered":"<p><img decoding=\"async\" title=\"Sicherheit (Pexels, allgemeine Nutzung)\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline\" alt=\"Sicherheit (Pexels, allgemeine Nutzung)\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2021\/04\/Sicherheit_klein.jpg\" width=\"200\">[<a href=\"https:\/\/www.borncity.com\/blog\/2022\/04\/21\/microsofts-defender-bemkelt-google-chrome-updates-als-malware-april-2022\/\" target=\"_blank\" rel=\"noopener\">German<\/a>]Microsoft's <a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365\/security\/defender-endpoint\/microsoft-defender-endpoint?view=o365-worldwide\" target=\"_blank\" rel=\"noopener\">Defender for Endpoint<\/a> (an enterprise security platform, see <a href=\"https:\/\/borncity.com\/win\/2022\/04\/01\/kein-durchblick-bei-defender-bezeichnungen-hier-werden-sie-geholfen\/\">Got lost in Defender? There is something like a Defender Cheat Sheet available<\/a>) seems to have run a bit amok once again. Administrators reported that since April 20, 2022, Defender has suddenly deemed updates for the Google Chrome browser as malicious and quarantined them. <\/p>\n<p><!--more--><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" src=\"https:\/\/vg02.met.vgwort.de\/na\/3420452fd4354f14b11cee775c9b8e14\" width=\"1\" height=\"1\">The first reports can be found on <a href=\"https:\/\/twitter.com\/thiskevgray\/status\/1516537571823738883\" target=\"_blank\" rel=\"noopener\">Twitter<\/a>, for example, where Kevin Gray informs Microsoft that Microsoft Defender for Endpoint is currently running amok.<\/p>\n<p><a href=\"https:\/\/twitter.com\/thiskevgray\/status\/1516537571823738883\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" title=\"Defender false Google Chrome Update alarm\" alt=\"Defender false Google Chrome Update alarm\" src=\"https:\/\/i.imgur.com\/RgYrjmT.png\"><\/a><\/p>\n<p>There are also reports on Reddit.com that confirm this erratic behavior of Microsoft Defender for Endpoint. For example, <a href=\"https:\/\/www.reddit.com\/r\/sysadmin\/comments\/u7fqlc\/defender_epp_blowing_up_on_google_updater\/\" target=\"_blank\" rel=\"noopener\">this post<\/a> states:<\/p>\n<blockquote>\n<p>Defender EPP Blowing Up on Google Updater?<\/p>\n<p>UPDATE: It does appear to be a false positive, likely triggered by a .dll being unsigned in the latest Google Updater service.  <\/p>\n<p>Just starting to see EPP hit on suspicious services, however all these seem to be legitimate updating operating on Google applications.<\/p>\n<\/blockquote>\n<p>Defender detects a file goopdate.dll or the associated service as malicious and blocks it. The problem is confirmed by other users in the thread. More threads from April 20 can be found <a href=\"https:\/\/www.reddit.com\/r\/sysadmin\/comments\/u7ghbi\/is_defender_flagging_chrome\/\" target=\"_blank\" rel=\"noopener\">here on reddit.com<\/a> and on <a href=\"https:\/\/twitter.com\/LongDogSecurity\/status\/1516528454971367429\" target=\"_blank\" rel=\"noopener\">Twitter<\/a>. Affected users will receive a warning: <\/p>\n<blockquote>\n<p>Multi-stage incident involving Execution &amp; Defense evasion<\/p>\n<\/blockquote>\n<p>Microsoft was informed about the false alarm via the above-mentioned tweets. The colleagues from Bleeping Computer picked up on the whole thing in <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/microsoft-defender-flags-google-chrome-updates-as-suspicious\/\" target=\"_blank\" rel=\"noopener\">this article<\/a> and write that Microsoft has already fixed the problems. A Microsoft spokesperson is quoted in the article:<\/p>\n<blockquote>\n<p>We have determined that these are false positives and have updated the logic for this alert to address the issue, which some customers may have experienced.<\/p>\n<\/blockquote>\n<p>This is not the first case of false positives by Defender (see also links at the end of the article). The Bleeping Computer article also cites several past examples. Anyone from the blog's readership who was affected by this false alarm?<\/p>\n<p><strong>Similar articles:<br \/><\/strong><a href=\"https:\/\/borncity.com\/win\/2022\/03\/17\/microsoft-defender-erkennt-office-updates-als-ransomware-aktivitten-16-3-2022\/\">Microsoft Defender falsely detected Office updates as ransomware activity (03\/16\/2022)<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2022\/03\/03\/microsoft-defender-meldet-flschlich-trojaner-auf-dell-rechnern-2-3-2022\/\">Microsoft Defender falsely reports Trojans on Dell computers (March 2, 2022)<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2022\/04\/12\/defender-signaturen-verursachen-extreme-ram-auslastung\/\">Defender signatures cause extreme RAM usage (April 2022)<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2022\/03\/31\/microsoft-warnt-vor-defender-spoofing-schwachstelle\/\">Microsoft warns of (fixed) Defender spoofing vulnerability<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2022\/02\/22\/windows-10-ungewollte-neustarts-wegen-microsoft-defender-application-control-wdac\/\">Windows 10: Unwanted reboots due to Microsoft Defender Application Control (WDAC)<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2022\/02\/11\/microsoft-fixt-wohl-heimlich-schwachstelle-im-defender-unter-windows\/\">Microsoft probably secretly fixes vulnerability in Defender under Windows<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2021\/12\/31\/windows-defender-fixes-probleme-und-log4j-scanner-fehlalarme\/\">Windows Defender: Fixes, Issues and Log4j scanner false alarms<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2021\/12\/01\/microsoft-defender-version-1-353-1874-0-meldet-flschlich-trickbot-emotet\/\">Microsoft Defender Version 1.353.1874.0 version 1.353.1874.0 incorrectly reports Emotet<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2022\/04\/01\/kein-durchblick-bei-defender-bezeichnungen-hier-werden-sie-geholfen\/\">Got lost in Defender? There is something like a Defender Cheat Sheet available<\/a><a href=\"https:\/\/www.borncity.com\/blog\/2022\/04\/01\/kein-durchblick-bei-defender-bezeichnungen-hier-werden-sie-geholfen\/\">!<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]Microsoft's Defender for Endpoint (an enterprise security platform, see Got lost in Defender? There is something like a Defender Cheat Sheet available) seems to have run a bit amok once again. Administrators reported that since April 20, 2022, Defender has &hellip; <a href=\"https:\/\/borncity.com\/win\/2022\/04\/21\/microsofts-defender-bemkelt-google-chrome-updates-als-malware-april-2022\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580],"tags":[780,773],"class_list":["post-24152","post","type-post","status-publish","format-standard","hentry","category-security","tag-chrome","tag-defender"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/24152","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=24152"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/24152\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=24152"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=24152"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=24152"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}