Trojan:Win32/BlockMsav.A!reg threat detected

Is the Trojan:Win32/BlockMsav.A!reg threat dangerous? In some cases yes, but if you blocked Windows Defender (msmpeng.exe) with GlassWire then it’s most likely a false positive.

To solve the issue, unblock msmpeng.exe as shown below (search for Antimalware and it will appear). If you click the icon next to its name it will show the app name as msmpeng.exe.

We white list Windows Defender to avoid this scenario but it appears Microsoft recently updated the publisher that signs Windows Defender so GlassWire could not recognize the executable.

Our next update will solve the issue by white listing the newly signed Windows Defender msmpeng.exe.

If you are not using GlassWire and you found this page from the web then perhaps Windows Firewall is probably blocking Windows Defender. You should go to Windows Firewall and choose “restore defaults” then reboot and see if the error goes away.

It’s also possible in some cases (especially if you are not running GlassWire) you may legitimately have this malware and you should do as Windows Defender suggests to solve the problem.

any eta on this fix?
i do have the antimalware executable allowed in glasswire (it even has a little shield to the left of it.
however defender keeps picking up the msav.A! alert been like thsi for over a year… when is this going to be fixed?

thanks

2.1.167 elite on win 10 pro 1909

@krevvy

This is a new issue that just appeared recently due to a change with how Microsoft signs Windows Defender.

We had this happen once before in 2018 and it was quickly fixed February 13, 2018. If you have this issue from 2018 then I’d suggest waiting until our next update that we’ll post in the forum.

Once the update is available please uninstall GlassWire in add/remove programs, then go to Windows Firewall and choose “restore defaults”. Now reboot.

Then reinstall GlassWire with its “reset firewall” option checked. If you continue to have that error after all that then it’s not related to GlassWire at all.

Hi Ken, thanks, i didnt really want to reset, but have been getting it constantly, and also saw about another issue of duplicate store apps…

so to try and kill 2 birds with 1 stone, have today reset & removed & reinstalled clean install of glasswire.

Will see how it goes over the next few weeks

p.s when triggering the uninstall of glasswire, windows defender popped up again with the MSAV warning.

fingers crossed

1 Like