Additional Microsoft Defender tools and services that provide security across various platforms and environments
Status updates for Microsoft Defender malware analysis submissions are not available through this forum. Status and any resulting definition changes are tracked through the Microsoft Security Intelligence submission site.
To check the status and provide any additional information:
- Go to the Microsoft Security Intelligence submission site at https://www.microsoft.com/wdsi/filesubmission.
- Sign in with the same account that was used to submit the file.
- Review the submission history to see the current state and any feedback from Microsoft.
For digitally signed applications that are still being detected as malicious:
- Ensure the file was submitted as a false positive, including clear justification and details about the publisher (Computer Care, LLC) and that it is signed using Azure Trusted Signing.
- If the detection source is Microsoft Defender for Endpoint (EDR or Antivirus), follow the guidance to:
- Submit the false positive to https://aka.ms/wdsi as documented in the Defender for Endpoint false positive guidance.
- Optionally configure a temporary workaround such as an "allow" indicator or an antivirus exclusion, scoped only to the affected file, while waiting for Microsoft to update definitions.
- If the file was detected in a SharePoint/OneDrive/Exchange scenario (for example via Safe Attachments or Defender for Endpoint signature detection), submit the file via the appropriate Submissions page in the Defender portal or via the Microsoft Security Intelligence portal, as described in the false-positive malware detection guidance.
If the file continues to be flagged after Microsoft confirms a false positive and updates definitions, contact Microsoft Support and specify that this is a recurring false positive for a digitally signed application.
This forum cannot directly access or modify Defender intelligence submissions; all interaction with the Defender intelligence team for existing submissions is done through the Microsoft Security Intelligence submission site and, if needed, via a support case.
References: