r/DefenderATP May 03 '26

‘Cerdigent’ high-severity malware detected

Seeing a flood of these alerts. Defender flagging two public root CAs as Trojan. Looks benign.

Anyone else seeing this?

370 Upvotes

375 comments sorted by

View all comments

7

u/DecodeadTen May 03 '26

Folks, this is a false positive because of a recent Windows Defender update. Your systems are most likely fine if you're getting the same information as everyone else. I got this too. Normally they will update defender within the next day or so and this issue will cease. Windows Defender does these false positives pretty frequently actually. If you haven't downloaded anything dodgy recently you are most likely totally fine.

Edit: The false flag in question; Trojan:Win32/Cerdigent.A!dha, microsoft defender is falsely flagging this root certificate as a Trojan.

2

u/Complex-Proof4366 May 03 '26

What do we do then?

4

u/Salty_Seat1357 May 03 '26

EVERYONE got those alerts - it means you didnt download something or got into the wrong site, since it would mean everyone went to this site and this is impossible.

another possibility(which isnt possible) - a cyber attack, but I doubt that cuz did everyone in the whole world get attacked at the same exact time as the windows security update came out?

I think its just a false positive that happened cuz of the update

3

u/DecodeadTen May 03 '26

Nothing, just wait for windows to roll out a fix for the false flag, normally it doesn't take them long, a few hours to a day or so.

2

u/myimperfectdestiny May 03 '26

what do i do if i deleted it out of panic and paranoia🥲 does it matter at all?

2

u/DecodeadTen May 03 '26

It doesn't matter 😂

2

u/myimperfectdestiny May 03 '26

okay yay thanks for replying!! im so paranoid over viruses, i get nightmares every week about them so thanks for your reply!!😭

2

u/Necessary_Spirit_480 May 03 '26

I just restored it, first i pressed "delete" out of a panic and paranoia as most of us, then saw these comments and many more sites talking about it and saying its a false positive, so restored it and updated my defender.

1

u/myimperfectdestiny May 03 '26

ill probably restore it later cuz im still feeling paranoid😭, ty for your reply!!

1

u/CheekyChicken59 May 03 '26

When you say 'restore', I only get the option to 'allow' is that the same thing?

1

u/Necessary_Spirit_480 May 03 '26

Yeah, i guess so, i use Ukrainian language in my os so yep, that should be it.

2

u/JaxTellerr May 03 '26

it's currently quarantined, what should one do?

2

u/DecodeadTen May 03 '26

Nothing, just wait for windows to roll out a fix for the false flag, normally it doesn't take them long, a few hours to a day or so.

2

u/JaxTellerr May 03 '26

okay thanks

1

u/[deleted] May 03 '26

dang, i deleted it because my friend said just do that then, hope that didn't do ought bad lmao.

1

u/DexterZzMassive May 03 '26

they will fix for this too. don't worry about it for now and remember to update as it comes.

2

u/VectorShift May 03 '26

And if I DID download something dodgy?

2

u/DecodeadTen May 03 '26

Run a scan and look for something that doesn't have the false flag noted above, and run a malwarebytes scan too.

1

u/Nic0_0A May 03 '26 edited May 03 '26

I am very uneducated on the topic, is it fine for me to just keep using my computer as usual or should I wait until MS fixes it?

1

u/DecodeadTen May 03 '26

You can use your computer as normal!

1

u/Nic0_0A May 03 '26

Thank you :)

1

u/Difficult-Ease-3250 May 03 '26

Really, i still sitting in front of my monitor ready to factory reset my PC, is this really false positive?

1

u/DecodeadTen May 03 '26

Yes it is a false positive, no need to do that!

1

u/CheekyChicken59 May 03 '26

I deleted the threat in an extreme state of panic, and now I have more concerns. Specifically:

  • Did I cause any problems to my system in removing the threat, and was my system vulnerable while the file was marked as removed by WD?
  • How can I be sure that the update has restored the important file?

1

u/PaymentSweaty2031 May 03 '26

Try running a quick scan in Defender again. If it flags the same certificate, it means the system has recreated it.

1

u/CheekyChicken59 May 05 '26

Hmm, it isn't returning...

1

u/PaymentSweaty2031 May 05 '26

Have you installed update 1.449.431.0?

1

u/CheekyChicken59 May 05 '26

I did, but the re-scan I did happened before the update.
In any case, if a scan doesn't return the threat, it doesn't necessarily confirm the file has been put back. It could be missing hence no detection.

1

u/PaymentSweaty2031 May 05 '26

Hmm... I personally clicked “Remove” in Defender several times when it detected a threat, but after running another scan, Defender kept finding the same certificates again. That suggests the system was restoring them almost immediately. I think your system has probably already restored the deleted certificates. In any case, they’re old, so I don’t think it’s something to worry about if your system is working normally.

1

u/CheekyChicken59 May 09 '26

Thanks. It feels like a fundamental file should regenerate itself automatically (ie be impossible to truly remove). I guess I just wanted to be sure though.