Issue Behavior:Win32/Hive.ZY

Behavior:Win32/Hive.ZY

Behavior:Win32/Hive.ZY is a generic threat detection used by the Microsoft Defender Antivirus (formerly the Windows Defender). It is supposed to signal the presence of potentially threatening files that have displayed suspicious behavior. However, unlike most generic detections, seeing a file flagged as Behavior:Win32/Hive.ZY doesn't necessarily mean that your system has been infected with a malware threat. 

This is exactly what happened when Windows users began seeing a warning about a threat detected as Behavior:Win32/Hive.ZY on their systems. Many were rightfully worried that they may experience security breaches, data theft, or other serious consequences typically associated with a malware infection. After all, the pop-up listed the threat as 'severe.' The situation seemed even grimmer after users try to fix the problem by letting Microsft Defender block the supposed threat, only to see the same warning popping up not long after. Some users reported receiving the next Behavior:Win32/Hive.ZY warning just 20 seconds later. 

The false positive appears to have been caused by a bug introduced with Microsoft Defender's Definition/Update Version 1.373.1508.0. The problem causes incorrect detections to occur when scanning Chromium-based browsers and Electron-based applications, such as Whatsapp, Discord, Spotify, and others, which are used by hundreds of millions of computer users across the world. Users are advised to update the Microsoft Defender as soon as possible. 

Loading...