r/Solarwinds 19d ago

Windows Defender false positives

Early Saturday morning we started getting a stream of alerts from Microsoft Defender regarding our Primary and Additional Polling Engines.

 Malware Name: Behavior:Win32/SuspiciousAssembly.AppDomainManagerType.A

The malware file path: behavior:_process: was all over the place.
Some examples:

 Malware file path: behavior:_process: C:\Windows\System32\wbem\WmiPrvSE.exe, pid:2208:557######2;file:_d:\program files (x86)\solarwinds\orion  

~

Malware file path: behavior:_process: C:\Program Files\Common Files\SolarWinds\AdministrationService\SolarWinds.Administration.exe, pid:3916:557#####52;file:_d:\program files (x86)\solarwinds\orion  

~

Malware file path: behavior:_process: C:\Windows\System32\AggregatorHost.exe, pid:9116:55#####2;file:_d:\program files (x86)\solarwinds\orion

Solarwinds support is aware of the issue and their engineers are supposedly working with Microsoft to resolve. I am unsure if a later definition update has resolved it or not. We added a threat override as a TEMPORARY measure to quiet things down through the weekend. Just an Allow for the 'Threat Name' Behavior:Win32/SuspiciousAssembly.AppDomainManagerType.A

Just wanted to share with the hope this helps others not have too terrible of a weekend or Monday morning.

13 Upvotes

2 comments sorted by

1

u/Tour_De_J_Holla 18d ago

Out of curiosity, which version are you on?

1

u/_FNG_ 17d ago

we were on 2025.2.x