Windows Defender Identifies The SAME PUP As A Threat Repeatedly

Anonymous
2020-06-16T21:00:07+00:00

Since the implementation of W10 V2004, Windows Defender has now been defaulted to identify

PUPS as a threat.  As a result, many are now made aware of their presence.  And they are "remediated",

on the spot, to prevent them from causing any mischief.

The problem occurs on the subsequent scans with Windows Defender. It identifies the same PUP again,

and again. It has been determined that this is caused by the presence of the PUP in Protection History.

It appears that the default remediation that Windows Defender applies to PUPs is to Block them,

then leave them in Protection History .

EDIT:  It has been found that malware other than PUPS, can require this same procedure.

           Some have discovered, that even Trojans exhibit this same characteristic, when remediated by

          Windows Defender in W10 v2004.

If you have any malware, remediated by Windows Defender, that alerts repeatedly, this procedure applies to

it as well. In order to cleanup the malware completely, find the file in the "container file" in the Protection

History record, and delete the file that is described. If you can't find or access the file, run the Microsoft

Safety Scanner. It uses the same definitions as Windows Defender, and should remediate  the file.

https://docs.microsoft.com/en-us/windows/security/threat-protection/intelligence/safety-scanner-download 

Then proceed to delete the Protection History info.

END EDIT.

Windows Defender is defaulted to scan its own "Scans/History". Resulting in the discovery of the malware over

and over again.  Even though, other scanners see no evidence of the malware on the PC.       It doesn't exist!

Until Microsoft sees fit to fix this problem,  you can prevent the repeating error indication, by deleting the

items that are described in Windows Defender Protection History. You can delete them by accessing their files,

that are located in C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service.

In the "Service" folder, find and delete "Detection History"

Note:  ProgramData is a hidden file. In order to access it, the "Hidden Items" option in "File Explorer" must be

checked.  Find the "Hidden Items" check box under the "View Tab".

And, the first time that you access "Scans", you must select "continue", to obtain the permission.

Restart and try another scan.    Notifications for the current malware should stop.  

However, this program miscue will probably reoccur, when the next PUP / Malware is encountered.  

Glen

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

188 answers

Sort by: Most helpful
  1. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  2. Anonymous
    2020-09-25T08:41:19+00:00

    Hi Labeeb,

    MalwareBytes Free is a very good antivirus, to use as a virus scanner. Defender is also

    good, and it offers all of the protection that you need. Defender is part of the Windows

    system, and as such, the overhead from it on the system is minimal.  And it is free!

    While Defender and MalwareBytes premium are considered to be compatible, updates

    to one or the other can sometimes cause conflict.       

    Glen

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2020-09-23T22:09:17+00:00

    Hi Labeeb,

    I'm sorry that you are having so much difficulty expanding Scans.

    Your problem might be associated with your Account that you use to access your PC.

    Since Scans does requires permission, the first time that you access it, it may also

    require that your Account is an Administrative Account.

    Do you know what kind of an Account that you run from? If it is not as an administrator,

    you may need to establish a new "Administrative Account" in order to delete Detection

    History.      If that is feasible.

    If that is not feasible, there is a "Windows PowerShell Admin" cmdlet that you can run,

    to purge Protection History. Which would delete the Detection History folder as well.

    However, it requires at least one full day to become effective.

    If you want to give that a try, proceed as follows.

    Right click "Start", and from the list, select "Windows PowerShell (Admin)".

    On the PowerShell screen type   Set-MpPreference -ScanPurgeItemsAfterDelay 1 <enter>

    Then type Exit   and hit <enter>  to exit PowerShell.

    After a day, Protection History should be empty.   And the alert from Defender should stop. 

    Follow up by running PowqerShell Admin again, but this time the cmdlet should be

    Set-MpPreference -ScanPurgeItemsAfterDelay 1E. <enter>

    Exit   <enter>    This sets the purge schedule to 30 days, which is normal.

    Best of luck,  Glen

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  4. Anonymous
    2020-08-20T19:39:13+00:00

    Hi Steve,

    Sorry, I should not have left out the instruction, that answers your question.

    The first time that you access "Scan", you must click "Continue" in the popup.

    This gives you permission to access "Scan" now, and for evermore.

    You may need to be operating from an "Administrator" account.

    The objects identified in Protection History, show a "container file", that describes

    the location of the file that was detected. If Defender, or any other scanner that you

    have employed, has failed to delete that file, you can explore to the location described,

    and manually delete it.  In the case of "PUPs", this is probably so.

    Glen

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  5. Anonymous
    2020-08-12T02:58:37+00:00

    Hello, Glen, I would like to give my feedback! I followed your instructions to navigate to C: \ Program Data \ Microsoft \ Windows Defender \ Scans \ History \ Service \ DetectionHistory and deleted the DetectionHistory folder. It really worked! Windows Defender has stopped showing the same PUP as a threat repeatedly. Thank you for your help.

    Pedro Manoel Ferreira

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments