Serious Discussion Did Microsoft Defender change the way it responds to file downloads?

Microsoft Defender
87 Replies 5,005 Views

nickstar1

Level 20
Verified
Top Poster
Well-known
I got bored and decided to test Microsoft Defender, but I noticed something strange. When I downloaded several malicious EXE files, Microsoft Defender didn't block or quarantine them during the download. Instead, Defender only detected them after I actually ran or executed the files. I also noticed that VirusTotal showed Microsoft Defender detecting the threats, so the files were clearly being recognized as malicious by Defender's engine. Has Microsoft changed the way Defender detects malware? Does it now require a malicious file to be executed before it detects it, similar to how some behavioral detection works in Malwarebytes? Or should Defender still be detecting and blocking known malicious EXE files before they are executed?

My system is clean, and I even performed a clean installation of Windows. I also used ConfigureDefender with the settings configured to High, and all of the relevant protection settings appeared to be enabled.I'm trying to understand whether this is normal behavior with the current version of Microsoft Defender or if something might be misconfigured on my system. Before, Microsoft Defender would detect and block malicious files while they were being downloaded, before I had a chance to run or execute them. Now, however, it seems like Defender is allowing the files to finish downloading and only detects them after I execute them.
 
I got bored and decided to test Microsoft Defender, but I noticed something strange. When I downloaded several malicious EXE files, Microsoft Defender didn't block or quarantine them during the download. Instead, Defender only detected them after I actually ran or executed the files. I also noticed that VirusTotal showed Microsoft Defender detecting the threats, so the files were clearly being recognized as malicious by Defender's engine. Has Microsoft changed the way Defender detects malware? Does it now require a malicious file to be executed before it detects it, similar to how some behavioral detection works in Malwarebytes? Or should Defender still be detecting and blocking known malicious EXE files before they are executed?

My system is clean, and I even performed a clean installation of Windows. I also used ConfigureDefender with the settings configured to High, and all of the relevant protection settings appeared to be enabled.I'm trying to understand whether this is normal behavior with the current version of Microsoft Defender or if something might be misconfigured on my system. Before, Microsoft Defender would detect and block malicious files while they were being downloaded, before I had a chance to run or execute them. Now, however, it seems like Defender is allowing the files to finish downloading and only detects them after I execute them.
I have a worse scenario; once MD did not detected the exe file after being downloaded and after being manually scanned, although it flags it on VT.
 
I got bored and decided to test Microsoft Defender, but I noticed something strange. When I downloaded several malicious EXE files, Microsoft Defender didn't block or quarantine them during the download. Instead, Defender only detected them after I actually ran or executed the files. I also noticed that VirusTotal showed Microsoft Defender detecting the threats, so the files were clearly being recognized as malicious by Defender's engine. Has Microsoft changed the way Defender detects malware? Does it now require a malicious file to be executed before it detects it, similar to how some behavioral detection works in Malwarebytes? Or should Defender still be detecting and blocking known malicious EXE files before they are executed?

My system is clean, and I even performed a clean installation of Windows. I also used ConfigureDefender with the settings configured to High, and all of the relevant protection settings appeared to be enabled.I'm trying to understand whether this is normal behavior with the current version of Microsoft Defender or if something might be misconfigured on my system. Before, Microsoft Defender would detect and block malicious files while they were being downloaded, before I had a chance to run or execute them. Now, however, it seems like Defender is allowing the files to finish downloading and only detects them after I execute them.


Hi, Defender should not generally require a known malicious EXE to execute before detecting it. What you observed can happen, but it does not by itself show that Microsoft changed Defender into execution-only protection. It more likely means the download did not trigger—or did not produce a verdict from—the expected file-scanning path, while access at execution did.

Why the timing can differ​

VirusTotal is not a reliable prediction of what Defender on your PC must do at download time. Its Microsoft result may use a different signature or cloud state, scan the completed file later, and lack the same file origin and delivery context. A VirusTotal detection confirms recognition in that particular scan; it does not prove your local Defender had the same verdict when the download completed.

Defender has several opportunities to intervene: browser or reputation checks, scanning when a file is written or closed, later background scanning, and scanning when the file is opened or executed. Execution can therefore be the first moment at which Defender blocks a file without implying that only behavioral detection is active.

Also distinguish the download finishing from the payload running successfully. If launching it immediately produced a Defender alert and quarantine, Defender may have blocked access before meaningful execution. Protection History and Event Viewer are better evidence of the detection stage than the visible timing of the notification.

Checks that isolate the problem​

Do not execute more live malware for testing. Use the harmless EICAR test file or another vendor-provided test artifact, then change one variable at a time.

  1. Check Windows Security status directly. Under Virus & threat protection settings, confirm Real-time protection, Cloud-delivered protection and Automatic sample submission are enabled. Under App & browser control, check reputation-based protection as well; that layer is separate from antivirus scanning.
  2. Check exclusions and conflicts. Review Defender exclusions and confirm no other antivirus is registered. In PowerShell, `Get-MpComputerStatus` can show whether antivirus, real-time and behavior monitoring are enabled; `Get-MpPreference` can reveal exclusions and relevant scan preferences. Redact usernames and paths before posting output.
  3. Temporarily return ConfigureDefender to its Windows defaults, reboot, and repeat only the harmless test. “High” is a third-party policy preset, not proof that every local protection path is functioning. If defaults restore download-time detection, the preset or a resulting policy deserves inspection.
  4. Compare browsers with the same harmless test. If only one browser differs, its download handling or reputation integration becomes more likely. If all browsers behave identically, concentrate on Defender policy and service state.
  5. Examine Protection History and `Applications and Services Logs > Microsoft > Windows > Windows Defender > Operational`. Note the detection time, action, file path and whether remediation occurred—never upload or share the malware itself.

If EICAR is detected when saved or extracted, but those samples were caught only when opened, that does not establish a general Defender failure; the individual files, archive/container handling, cloud verdict timing and delivery method matter. If EICAR also remains untouched until launch, despite real-time protection being reported active, that is strong evidence of a configuration or protection-path problem rather than normal expected behavior.

Practical conclusion​

Defender still uses pre-execution scanning and reputation controls; execution is not supposed to be a universal prerequisite for detecting known malware. The precise cause here cannot be assigned from notification timing or VirusTotal alone.

Because live malicious files were executed, a clean installation performed afterward addresses that installation, but further live testing is an unnecessary gamble. If any sample ran before Defender intervened—or if there is doubt whether it did—disconnect that test system from sensitive accounts and use the MalwareTips Malware Removal Assistance team for individualized checking. A negative scan would not conclusively settle an actually executed sample.
 
This is strange. I also tested it with non-EXE files, and Microsoft Defender still isn’t detecting or blocking the threats when the files are downloaded. It only detects them when I try to execute the files or manually scan them. Is this normal behavior? Can anyone explain why this is happening? It definitely didn’t used to work this way for me. Yeah, Microsoft Defender isn’t detecting anything until the file is either scanned or executed. I’m not sure why Defender is behaving this way. I’ve tested several more samples, and I’m still seeing the same behavior. It’s pretty odd. No matter what samples get downloaded they have to be executed or right click scanned for a detection to occur it's strange...

Screenshot 2026-09-12 183803.pngScreenshot 2026-09-12 183827.png
 
Does Windows Defender detect EICAR test files? Mine doesn’t seem to detect them automatically, as shown in my proof. It only detects the file when I right-click it and select “Scan with Microsoft Defender.” Is this normal? It seems pretty crazy that it doesn’t detect the file immediately. it allowed them all to download. It's not even blocking Eicar test files when i bypass edges warning to download it just allows it to download no problem. edge detects it but Microsoft security does not.
 

Attachments

  • Screenshot 2026-09-12 184913.png
    Screenshot 2026-09-12 184913.png
    333.5 KB · Views: 56
  • Screenshot 2026-09-12 184924.png
    Screenshot 2026-09-12 184924.png
    67.2 KB · Views: 59
Does Windows Defender detect EICAR test files? Mine doesn’t seem to detect them automatically, as shown in my proof. It only detects the file when I right-click it and select “Scan with Microsoft Defender.” Is this normal? It seems pretty crazy that it doesn’t detect the file immediately. it allowed them all to download. It's not even blocking Eicar test files when i bypass edges warning to download it just allows it to download no problem. edge detects it but Microsoft security does not.

I don't know if and what's changed, as I just started using WD about 4 days ago. It is flagged when I scan it, but not on download using FF.
F-Secure was the same way with a couple of these EICAR test files.
 
On my side, happened once or twice; the rest are detected once downloaded, or even before start of download if using Edge

I don't know if and what's changed, as I just started using WD about 4 days ago. It is flagged when I scan it, but not on download using FF.
F-Secure was the same way with a couple of these EICAR test files.
Before, Microsoft Defender would completely block a malicious download and wouldn’t even allow the file to be saved in the Downloads folder. I’m not sure why they decided to change that behavior. Personally, I think it feels much better and safer when malicious files are blocked completely before they ever make it into the Downloads folder, rather than being downloaded first and then detected or removed afterward. Alright, all you hardcore Microsoft Defender users can you explain what’s going on here? When did Defender start making all these changes? I haven’t used Defender since around 2022, and back then, if I downloaded an EICAR test file, Defender would detect and block it before it even made it into the Downloads folder.

Now I’m seeing completely different behavior, and I’m curious why. Did Microsoft change how Defender handles EICAR test files or downloaded threats? Was there a specific update or change in the way real-time protection works? Calling all the Defender experts, lol. What changed, and when did it happen?
 
Last edited:
WEB scanning is my #1 protection requirement behind ad-blocking. I scan my downloads folder after every time I download updates so I'm so fresh and so clean.

Anyway as I've said most even the most technical user would and could not tell if they were infected by a advanced attacker using zero day exploits.

So take it easy, have a :emoji_beer:🍹🍺🍻🍸🍾🍷🥂 & have 🚬 or take a chill 💊 and watch cat videos on YouTube while AI detsroys the world.
 
WEB scanning is my #1 protection requirement behind ad-blocking. I scan my downloads folder after every time I download updates so I'm so fresh and so clean.

Anyway as I've said most even the most technical user would and could not tell if they were infected by a advanced attacker using zero day exploits.

So take it easy, have a :emoji_beer:🍹🍺🍻🍸🍾🍷🥂 & have 🚬 or take a chill 💊 and watch cat videos on YouTube while AI detsroys the world.

Love it, great humor, great wisdom :)
 
This is strange. I also tested it with non-EXE files
I downloaded it with Edge, and Microsoft Defender blocked it. I downloaded it with Firefox, and Microsoft Defender didn’t. I quickly scanned the file, and Microsoft Defender detected it. I downloaded the ZIP file, and the quick scan didn’t detect it, probably because it didn’t unpack.

Did you download it with Edge?

P.S. I make sure that my daily scans succeed, which some people here think is 🤪. Multilayered security is the word.
 
I don't know if and what's changed, as I just started using WD about 4 days ago. It is flagged when I scan it, but not on download using FF.

The issue with Firefox is known for years. It is not supported by Microsoft Defender "Block At Firtst Sight" feature.
 
Just to be clear, I downloaded them all using Edge, not Firefox. It's so strange how it behaves now it's still protecting my system, but I really wish threats were blocked at download rather than at execution. Is it even worth it to report this to microsoft?

Going back to AVG, Windows Defender just feels clunky, slow, and incomplete, and it leaves a lot to be desired. It wouldn’t hurt for Microsoft to give Defender some renewed attention and make some much-needed improvements to both the GUI and the overall performance of the application. It feels unnecessarily slow and cumbersome at times. Considering Windows Defender is developed by Microsoft specifically to operate within the Windows ecosystem, you would expect it to be more polished, responsive, and efficient. A product designed by Microsoft to work within its own environment should function much better than it currently does.

Yes, the product is certainly better than nothing, and it offers much more than we had back in the day. However, I wish Microsoft would put more focus into it and make the changes and improvements it really needs. For now, I’m leaving Defender behind until Microsoft makes some serious changes and improvements.
 
Last edited:
The issue with Firefox is known for years. It is not supported by Microsoft Defender "Block At Firtst Sight" feature.
Yes, indeed.
Another reason why Firefox will always be my secondary browser, considering that I'm not interested in other antivirus (I'm already not very interested in MD :giggle:).
You're wrongly blaming Firefox for this. You should blame Microsoft. More specifically, for some weird reason, Defender isn't scanning downloads at all and instead starts running a scan when you try to run/open the file.

Edge uses SmartScreen and is closely connected with Defender hence why it will always work. Disable SmartScreen and there are huge chances it will behave just like any other web browser out there.

Keep in mind, just because Defender let the file through, doesn't mean you're any less protected. Malicious file sitting on disk isn't doing any damage whatsoever; in order to do any damage, it needs to be loaded into RAM. Defender still works because it scans the file when you try to open it; if it didn't and instead let it run normally, then we'd have a problem.
Just to be clear, I downloaded them all using Edge, not Firefox. It's so strange how it behaves now it's still protecting my system, but I really wish threats were blocked at download rather than at execution. Is it even worth it to report this to microsoft?
While technically it doesn't reduce your protection, I too prefer malware to be blocked before or during download. Defender does have ability to scan during download and it did so before, but it seems that it isn't working as of this moment. I tried to enable it in Group Policy and it didn't work; I think scan is broken.

If you have Microsoft account (and time), you can report the issue to Microsoft. Maybe someone even reported it before. As far as I know, this behavior is not normal. Recently, they did have issues with Defender components so it could be connected with that.
 
Last edited:
You're wrongly blaming Firefox for this. You should blame Microsoft. More specifically, for some weird reason, Defender isn't scanning downloads at all and instead starts running a scan when you try to run/open the file.

Edge uses SmartScreen and is closely connected with Defender hence why it will always work. Disable SmartScreen and there are huge chances it will behave just like any other web browser out there.

While technically it doesn't reduce your protection, I too prefer malware to be blocked before or during download. Defender does have ability to scan during download and it did so before, but it seems that it isn't working as of this moment. I tried to enable it in Group Policy and it didn't work; I think scan it broken.

If you have Microsoft account (and time), you can report the issue to Microsoft. Maybe someone even reported it before. As far as I know, this behavior is not normal. Recently, they did have issues with Defender components so it could be connected with that.
I also want to point out that the issue occurs in Microsoft Edge too. Even if I bypass the security warning and download the .exe file, Defender won’t detect it until it’s either executed or manually scanned, which is quite strange. i just want to clarify for everyone it's not only a Firefox issue it does the same thing in edge.
 
I also want to point out that the issue occurs in Microsoft Edge too. Even if I bypass the security warning and download the .exe file, Defender won’t detect it until it’s either executed or manually scanned, which is quite strange. i just want to clarify for everyone it's not only a Firefox issue it does the same thing in edge.
In that case, even more embarrassing for Microsoft. 100% it's a bug; this isn't normal behavior.

Could be related to this: https://www.neowin.net/news/microso...er-virus-scans-in-trying-to-fix-a-0-day-flaw/
 
Last edited:

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top