Free tools Windows power users keep installed
One-click scans. No signup required.
The widely reported Behavior:Win32/Hive.ZY alerts on September 4, 2022, were caused by a faulty Microsoft Defender security-intelligence update—not evidence by themselves that Chrome, Edge, or another trusted app was infected. Microsoft’s corrective definition was version 1.373.1537.0, released later that day. This is a historical incident, not a newly reported Windows problem in 2026.
What happened with Behavior:Win32/Hive.ZY?
Microsoft Defender added the Behavior:Win32/Hive.ZY detection in security-intelligence version 1.373.1508.0, released September 4, 2022, at 8:44:37 a.m. Microsoft’s release notes listed the detection as severe. The faulty rule repeatedly flagged normal behavior when some Chromium-based browsers and Electron applications opened or created runtime files. Microsoft’s [release notes for version 1.373.1508.0](https://www.microsoft.com/en-us/wdsi/definitions/antimalware-definition-release-notes?requestVersion=1.373.1508.0) document when the detection was added.
Behavior detections describe suspicious activity; the name is not necessarily the name of a conventional malware family or a particular malicious executable. In this incident, the reported pattern was a false positive: legitimate app activity was incorrectly classified by Defender. Reports included Google Chrome, Microsoft Edge, Discord, WhatsApp, Spotify, and other Chromium- or Electron-based programs. That does not establish that every app using either framework, or every Windows device, was affected. BleepingComputer’s incident report documented examples.
Which Defender update corrected the false positive?
Microsoft’s security-intelligence version 1.373.1537.0 was released September 4, 2022, at 9:27:55 p.m. Microsoft support documentation identifies that version as resolving the false positive. The release timestamps for the faulty and corrective definitions are about 12 hours and 43 minutes apart. Later definitions supersede those historical versions; 1.373.1537.0 is not a recommendation to install an old package today.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
See Microsoft’s release notes for version 1.373.1537.0 and the Microsoft Q&A discussion confirming the fix. This was a Defender security-intelligence update, not primarily a Windows 10 or Windows 11 cumulative operating-system update.
How to update Microsoft Defender
Use Windows Security
- Open Windows Security.
- Select Virus & threat protection.
- Under Virus & threat protection updates, select Protection updates.
- Select Check for updates and let Defender install available security intelligence.
Labels can vary slightly by Windows version, language, or managed configuration. The goal is to update Defender’s security intelligence, not to install a Windows feature update. On a current computer, install the available current definitions rather than trying to return to a 2022 version.
Rank #2
Use PowerShell
If you administer the device or cannot use the Windows Security interface, open PowerShell as an administrator and run:
Update-MpSignature
To inspect the installed Defender signature version and its last update time, run:
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsRank #3
Get-MpComputerStatus | Select-Object AntivirusSignatureVersion, AntivirusSignatureLastUpdated
Update-MpSignature requests a Defender signature update; it does not roll back or reinstall Windows. Microsoft’s Defender update-management documentation covers update administration.
If the update does not appear to work
- Confirm the device has internet access and retry Protection updates > Check for updates.
- Try
Update-MpSignaturein an elevated PowerShell session, then restart Windows if alerts continue. - Check the installed signature version rather than relying on the Windows build number or a general “up to date” message.
- Open Windows Security’s Protection history and note the detection name, time, and affected file path. A stale notification, a different detection, or an alert on a different file may not be the 2022 incident.
If an alert concerns an unknown download or persists outside the historical app-launch pattern, run a scan; use a Full scan or Microsoft Defender Offline scan if the circumstances warrant further investigation. Do not restore a quarantined file automatically. Verify that the application came from its official source and examine the file path and signature before considering restoration.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.When the 2022 false-positive explanation fits—and when it does not
The documented explanation is strongest when alerts began around September 4–5, 2022, after the 1.373.1508.0 definition, appeared as trusted Chromium or Electron apps launched, and stopped after Defender received the corrective definition. A scan reporting no persistent infection was consistent with reports from the incident, but it is not proof that a device has no other threat.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Best Value
Do not dismiss an alert just because its name contains “Hive.ZY.” An unknown or pirated application, a suspicious file path, a different detection name, or a similar warning appearing years later needs separate assessment. The 2022 fix does not establish that a modern alert is harmless.
What not to do
- Do not turn off Defender as the default workaround. Updating the detection rules addresses a faulty signature without leaving protection disabled.
- Do not add broad exclusions for Chrome, Edge, Discord, or the Downloads folder just to silence an alert.
- Do not uninstall trusted apps solely because they triggered this historical rule. Reinstalling an app would not correct Defender’s detection rule. If reinstalling is necessary for another reason, download it from the vendor’s official site.
- Do not bypass enterprise controls. Managed devices may receive Defender definitions through Intune, Configuration Manager, WSUS, Defender for Endpoint, or other organizational policy. Contact the security administrator if local updates are restricted.
For offline or air-gapped devices, use Microsoft’s current official Defender update guidance to identify the appropriate manual intelligence package for that operating system and architecture; an old 2022 package is not suitable as a current update.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




