# Windows Defender quarantined Slicer.exe

**URL:** <https://discourse.slicer.org/t/windows-defender-quarantined-slicer-exe/23613>\
**Category:** Support\
**Created:** [May 27, 2022, 7:00pm UTC](https://discourse.slicer.org/t/windows-defender-quarantined-slicer-exe/23613 "2022-05-27T19:00:36Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![lassoan](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.slicer.org/lassoan/32/13_2.png) [@lassoan](https://discourse.slicer.org/u/lassoan)\
**Post date:** [May 27, 2022, 7:00pm UTC](https://discourse.slicer.org/t/windows-defender-quarantined-slicer-exe/23613/1 "2022-05-27T19:00:36Z")

</div>

On my university-managed computer, Slicer.exe disappeared from the install tree. Windows Defender quarantined the executable due to “potentially unwanted behavior”.

![image](https://us1.discourse-cdn.com/flex002/uploads/slicer/original/3X/0/f/0f8abed7dbfc9992fda069d4537c63a266d2ba61.png)

It states that it detected `Program:Win32/Beareuws.A!ml`, which must be a false positive. I’ve submitted the executable to VirusTotal and nothing was detected (just one bogus engine out of 68 indicated “unsafe” without any more information).

@jcfr You have submitted false positives to Microsoft before. Would you be able to submit this Slicer5 `Slicer.exe` executable?

---

<div class="post-metadata">

**Author:** ![jcfr](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.slicer.org/jcfr/32/17825_2.png) [@jcfr](https://discourse.slicer.org/u/jcfr)\
**Post date:** [May 27, 2022, 7:23pm UTC](https://discourse.slicer.org/t/windows-defender-quarantined-slicer-exe/23613/2 "2022-05-27T19:23:25Z")

</div>

> You have submitted false positives to Microsoft before. Would you be able to submit this Slicer5 `Slicer.exe` executable?

I will engage with our security team and follow up.

---

<div class="post-metadata">

**Author:** ![jcfr](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.slicer.org/jcfr/32/17825_2.png) [@jcfr](https://discourse.slicer.org/u/jcfr)\
**Post date:** [June 10, 2022, 4:24pm UTC](https://discourse.slicer.org/t/windows-defender-quarantined-slicer-exe/23613/3 "2022-06-10T16:24:50Z")

</div>

The file has been submitted for analysis.

This was done following instructions published at [Address false positives/negatives in Microsoft Defender for Endpoint - Microsoft Defender for Endpoint | Microsoft Learn](https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/defender-endpoint-false-positives-negatives?view=o365-worldwide#part-4-submit-a-file-for-analysis)

### Results (as of 2022.06.10)

 ![image](https://us1.discourse-cdn.com/flex002/uploads/slicer/original/3X/4/a/4a9b1f44cac6f0ea93f84ccdd4192996838f0e54.png)

### Submitted information

The following information were provided:

- **Select the Microsoft security product used to scan the file** :  
`Microsoft Defender Antivirus (Windows 10)`

- **What do you believe this file is?**  
Incorrectly detected as PUA (potentially unwanted application)

- **Detection name** : `Program:Win32/Beareuws.A!ml`

- **Definition version (recommended)**:  
Unknown

- **Additional information:**

---

<div class="post-metadata">

**Author:** ![jcfr](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.slicer.org/jcfr/32/17825_2.png) [@jcfr](https://discourse.slicer.org/u/jcfr)\
**Post date:** [June 10, 2022, 4:25pm UTC](https://discourse.slicer.org/t/windows-defender-quarantined-slicer-exe/23613/4 "2022-06-10T16:25:26Z")

</div>

> [@jcfr](#):
>
> **Definition version (recommended)**:  
> Unknown

@muratmaga @lassoan Do you have more details regarding this ?

---

<div class="post-metadata">

**Author:** ![lassoan](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.slicer.org/lassoan/32/13_2.png) [@lassoan](https://discourse.slicer.org/u/lassoan)\
**Post date:** [June 10, 2022, 5:10pm UTC](https://discourse.slicer.org/t/windows-defender-quarantined-slicer-exe/23613/5 "2022-06-10T17:10:53Z")

</div>

For me it was the with the latest definition version as of 2022-05-25. I’m not sure if it’s still removes the executable. I’ve tried a manual scan of the Slicer folder and it did not do anything, but maybe because I’ve manually restored the file before.
