A false positive is a legitimate file, app, website, or domain classified as dangerous. Do not assume an alert is wrong because you recognize the name: malicious files and sites can imitate trusted ones.
Keep the item contained
- Choose Quarantine when possible. Do not restore, run, or permanently allow the item yet.
- Record the detection name, full file path or URL, and the time of the alert.
- Confirm where the file came from and whether it has the expected digital signature.
Use the correct review channel
- File or app detection: use the in-app feedback option when available, or open a Support request. Include the scan or protection log, a screenshot, the publisher, and why you expect the item to be safe.
- Website, URL, or domain: do not open a Support ticket. Submit the case through the Gridinsoft Portal false-positive form.
Do not upload confidential documents to public scanning services. Send a file sample only through the method requested by Support, and remove private query data or access tokens from URLs sent to Portal.
Restore only after review
For a file or app, if Support confirms the detection is incorrect, update the Threat List before restoring it. Create the narrowest possible exception only if the updated database still detects it. Prefer replacing an unsigned or unexpectedly changed file with a fresh copy from its official publisher. Website and domain cases follow the result of the Portal review.
For a more detailed procedure, see the complete false-positive guide.