Win64/LummaStealer.

Jaswinder Singh 0 Reputation points
2025-07-29T20:38:48.42+00:00

i am getting this multiple time a day. i scanned the file ( choice.exe) with ESET and Microsoft online as well no malware detectedimage

Microsoft Security | Microsoft Defender | Other
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Asher K 0 Reputation points
    2025-08-16T06:15:56.0533333+00:00

    It's a late response, but i've had this same thing with other malware before. It looks like what you have described is either a false positive or it's the actual malware. My mate had this malware recently, and it is extremely stubborn and can return once removed. Sometimes, remnants can be left behind and keep getting flagged after removal. If you haven't noticed any suspicious account activity, odd processes in task manager, and you never actually visited any unsafe sites/downloaded cracked software, you are likely in the clear. Just boot in safe mode and remove the files:

    1. Open windows search and type in "run"
    2. Once run has opened, type in "msconfig" and click enter
    3. Go to the "boot" tab and click "safe boot"
    4. Restart your pc manually if it doesn't restart automatically
    5. Then, once in safe mode, go to "C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service"
    6. Delete everything inside that file, but nothing else
    7. Then reopen "run"
    8. Type in "msconfig" again
    9. Go to the "boot" tab and select "normal boot" or "regular boot"
    10. Then restart your computer back into normal mode This should have deleted windows security history and it should stop detecting it. Hope this helps you, it took a very long time to type :)
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.