Writing an Exception in Windows Defender for Trojan:JS/CoinHive.B

Answer

The following instructions will guide staff through how to write an exception in Windows Defender for Trojan:JS/CoinHive.B.  This has proven to be a false threat, inaccurately triggering Windows Defender alerts on computers. 

Writing an Exception in Windows Defender

  1. Using the Search Bar located next to the Start button, type Virus & Threat Protection and hit the Enter key.  This will open the Virus & Threat Protection window.

A screenshot of a computer

Description automatically generated with medium confidence

 

  1. Once the Virus and Threat Protection window is open, select Manage Settings under Virus & Threat Protection Settings. 

Graphical user interface, text, application

Description automatically generated

  1. Scroll down the page until you see Exclusions.  Click Add or Remove Exclusions.  A page asking if you want this program to make changes to your device will open.  Select Yes

Graphical user interface, text, application

Description automatically generated

  1. Click Add an Exclusion.  In the dropdown menu, select Folder

Graphical user interface, application, Teams

Description automatically generated

  1. Type C:\ProgramData\FortiEDR\Config\Collector in the top bar.  Click once on the Signatures folder until Signatures shows in the bar below.  Once it does, click Select Folder.  You will see file path: C:\ProgramData\FortiEDR\Config\Collector\Signatures added to the list of exceptions and Windows Defender will no longer create alerts from content of this folder. 

Graphical user interface, text, application, email

Description automatically generated

Questions?

If you have any questions, contact the TSI Department at ask@nlls.ab.ca




Answered By: Tim Kuelker
Last Updated: Jan 10, 2023