Share via

Trojan:Win32/Cerdigent.A!dha

Daniel Sandlund 115 Reputation points
2026-05-03T11:33:57.02+00:00

Getting a Trojan warning Trojan:Win32/Cerdigent.A!dha

Looks like there are many getting this right now...

Is it a false possitive?

Microsoft Security | Microsoft Defender | Other

5 answers

Sort by: Most helpful
  1. _AW_ 67,251 Reputation points Volunteer Moderator
    2026-05-03T15:14:54.9+00:00

    Run Windows Update. This is resolved in the latest Microsoft Security definition update 1.449.430.0 and no longer detected.

    60+ people found this answer helpful.

  2. George Birbilis 0 Reputation points
    2026-05-03T14:51:57.1766667+00:00

    They're removing some root certificates that are being exploited:

    https://bugzilla.mozilla.org/show_bug.cgi?id=2033170

    10+ people found this answer helpful.
    0 comments No comments

  3. Andy Barker 0 Reputation points
    2026-05-03T14:03:15.8933333+00:00

    I am seeing this alert from Microsoft but not from SentinelOne or Arctic Wolf. Usually, in legitimate cases, all three are alerting me. I believe this could be a false positive.

    10+ people found this answer helpful.

  4. Q&A Assist
    2026-05-03T11:34:07.12+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    Trojan:Win32/Cerdigent.A!dha is detected as a trojan by Microsoft Defender. The context does not state that this specific detection is a known false positive.

    To handle a potential false positive in Microsoft Defender products, the supported process is:

    1. Determine the detection source (for example, Microsoft Defender Antivirus vs. EDR in Defender for Endpoint).
    2. If the file or process is believed to be clean, submit it to Microsoft for analysis as a suspected false positive at the Microsoft malware submission portal (https://aka.ms/wdsi).
    3. As a temporary workaround while waiting for analysis, an administrator can add an appropriate exclusion or an allow indicator for the specific file hash, if this is acceptable in the security policy.

    If the file is not known and not explicitly trusted, it should be treated as malicious and removed or quarantined by Defender.


    References:

    10+ people found this answer helpful.
  5. Mehrad Moradipour 0 Reputation points
    2026-05-04T08:28:31.99+00:00
    4 people found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.