(1) You found a work-around? To do non-trivial edits first? Good going, then.
(2) I like the virtues I itemized earlier on Windows Defender. I would leave it as the Real-Time scanner. Maybe install Malwarebytes - but do not activate its Real-Time scanning. Just run it occasionally On-Demand. And send them a check after you've done
it twelve times. IIRC, it found a bunch of PUPs first time I ran it, but nothing ever after. I uninstalled it after my 11th run. Defender catches/blocks all 3 items here...
http://rexswain.com/eicar.html
EICAR Test Virus

That's in Edge. In "Defender, Virus & Threat Protection, Protection History" I see (for the 2 .zip's that weren't blocked)...

Click "learn more" to see it really is a test. This site opens in Edge...
https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?name=Virus%3aDOS%2fEICAR_Test_File&threatid=2147519003
Virus:DOS/EICAR_Test_File
But why does it say "remediation incomplete"? Well, later it says "might
not". Anyway, the Downloads folder has no EICAR file at all in it - so, I guess it is completely gone. A Defender quick scan finds nothing. At first, under "Actions", there were choices to remove, quarantine, & allow on device. I chose "remove" - & now the
only choice left is "allow" - why is it left? I'm thinking, if I click "allow", it will put that file into the exclusions folder.
So - that proves Windows Defender works well. But how do I get those items out of Protection History now? I don't like extraneous items to be lying around.
Edit: Now I've run a full Defender scan, & it found EICAR junk in two folders that belong to Edge, which look like TIFs (Temporary Internet Files) & a temporary download folder....


I chose "remove", & they were deleted. (I checked before & after.) I guess those were harmless anyway (even in case they were real). Here is what the above looks like afterward...

Here is what TempState looked like before the remove...

I still think Defender is fine - but a tad sloppy. How do I get rid of this extraneous matter in Protection History? A reboot didn't do it. And why do those other two still say "remediation incomplete"?

Edit 8/19: I deleted the Microsoft-Windows-Windows Defender log in Event Viewer in an attempt to get rid of that Protection History, but the history did not go. There were two event ID 1117
that said a quarantine failed because the virus file could not be found. I don't recall asking for a quarantine, but I guess that explains the "remediation incomplete" on those two.