Microsoft Defender False Positive Assessment - Medical Healthcare CD Distribution

Federico Lutzu 0 Reputation points
2025-08-27T16:15:07.2833333+00:00

Microsoft Defender detected a file as "Trojan:Win32/Leonem!rfn" from an official medical CD distributed by ASL Cagliari (Italian Public Health Service). This CD contains DICOM medical imaging data and viewers for patient care.

File Details:

Conflicting Assessment:

Hospital IT department claims this is a false positive and legitimate medical software. However, the specific detection of Leonem trojan family raises security concerns for healthcare data protection.

Critical Need:

We urgently need Microsoft's definitive assessment to determine if this represents:

  1. A legitimate security threat requiring healthcare policy action
  2. A false positive requiring signature updates

This affects medical imaging workflow across Italian healthcare institutions, and multiple patients may have received identical CDs. Healthcare organizations require authoritative guidance from Microsoft to make informed security decisions.

Request: Please prioritize analysis and provide official Microsoft position on this detection for healthcare security guidance.

Microsoft Security | Microsoft Defender | Other
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.