Windows Defender Identifies The SAME PUP As A Threat Repeatedly

Anonymous
2020-06-16T21:00:07+00:00

Since the implementation of W10 V2004, Windows Defender has now been defaulted to identify

PUPS as a threat.  As a result, many are now made aware of their presence.  And they are "remediated",

on the spot, to prevent them from causing any mischief.

The problem occurs on the subsequent scans with Windows Defender. It identifies the same PUP again,

and again. It has been determined that this is caused by the presence of the PUP in Protection History.

It appears that the default remediation that Windows Defender applies to PUPs is to Block them,

then leave them in Protection History .

EDIT:  It has been found that malware other than PUPS, can require this same procedure.

           Some have discovered, that even Trojans exhibit this same characteristic, when remediated by

          Windows Defender in W10 v2004.

If you have any malware, remediated by Windows Defender, that alerts repeatedly, this procedure applies to

it as well. In order to cleanup the malware completely, find the file in the "container file" in the Protection

History record, and delete the file that is described. If you can't find or access the file, run the Microsoft

Safety Scanner. It uses the same definitions as Windows Defender, and should remediate  the file.

https://docs.microsoft.com/en-us/windows/security/threat-protection/intelligence/safety-scanner-download 

Then proceed to delete the Protection History info.

END EDIT.

Windows Defender is defaulted to scan its own "Scans/History". Resulting in the discovery of the malware over

and over again.  Even though, other scanners see no evidence of the malware on the PC.       It doesn't exist!

Until Microsoft sees fit to fix this problem,  you can prevent the repeating error indication, by deleting the

items that are described in Windows Defender Protection History. You can delete them by accessing their files,

that are located in C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service.

In the "Service" folder, find and delete "Detection History"

Note:  ProgramData is a hidden file. In order to access it, the "Hidden Items" option in "File Explorer" must be

checked.  Find the "Hidden Items" check box under the "View Tab".

And, the first time that you access "Scans", you must select "continue", to obtain the permission.

Restart and try another scan.    Notifications for the current malware should stop.  

However, this program miscue will probably reoccur, when the next PUP / Malware is encountered.  

Glen

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

188 answers

Sort by: Most helpful
  1. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  2. Anonymous
    2020-09-18T05:36:36+00:00

    thank you

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2020-09-15T00:58:46+00:00

    Hi Brian,

    Yunus had a similar problem, that didn't respond to the fix that has worked for so many.

    He seems to think that an update, took care of his problem. I have heard that a few others

    have had a similar experience.  We have always known, that the fix for this problem,

    would have to come from Microsoft. Since they more than likely caused it in the first place.

    My procedure is only a workaround for the program problem introduced by v2004.

    I believe that they have probably fixed the problem, by releasing the Antimalware 

    Platform update to version 4.18.2008.9-0.  Not sure why others are still having the

    problem, however. There must be other circumstances.

    I am not aware of the Motherboard incompatibility that you mention, but that is

    highly possible. Feature Updates exclude some PCs frequently.

    As you know, Windows Defender has detected and remediated your particular Trojan

    for quite a while. Your alert must be a false positive, of some sort. Especially, since

    other scanners do not detect it. The one way that I know is, the virus has already been

    remediated, but is left in Defender's Protection History, where only Defender can see it.

    You say that you have deleted Detection History, but that did not fix it. ???

    If you are ever able to re-install W10 v2004, and find this virus in Protection History,

    Download a copy of Microsoft Safety Scanner, which uses the same definitions as

    Defender, and perform a full scan, while in Safe Mode. If the virus is actually somewhere

    on your PC, the Safety Scanner should detect it, and remediate it.

    https://docs.microsoft.com/en-us/windows/security/threat-protection/intelligence/safety-scanner-download

    After the scan, examine Defender Protection History again. If you see the notification of

    the presence of the Trojan, then perform the procedure to delete it from Detection History.

    Re-examine Protection History, and you should not see any Trojan notification now.

    Windows Defender, using the same definitions as the Safety Scanner, should not detect it

    again. If it does, your suspicion that your problem resides in the hardware is probably correct.

    Best of luck,  Glen

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2020-09-14T22:53:41+00:00

    Glen,

    I am suffering from the same issue as Yunus and several others here since an update back in July or August. I've went through many guidelines in this thread, deleting detection history etc . I have tried Defender Offline scans, several Anti-malware software including Malwarebytes run in safe mode etc. Not one software detects the trojan that Windows Defender claims is on my PC.

    I have since performed a fresh install of Windows 10 and still receive notifications from Defender about this Trojan. I am currently stuck on Windows 1909 update as I don't believe my PC is compatible with the current update as of yet so I'm not sure if I can remediate the issue via updates. 

    Both my CPU and motherboard are outdated (roughly 10 years old). I read on this forum Microsoft Answers that people with a similar motherboard setup as myself were running into these issues with Defender as of late.

    Malwarebytes Employee (from a Reddit post)

    "I found several other recent posts from different people getting the same old Win32/Dorv.D!rfn torjan (which itself is from circa 2015 and not even UEFI based) assigned to different UEFI components. In other words, more evidence of a false positive."

    Is this correct? Should we be expecting an update from Microsoft at some point in the future to correct this? 

    Several recent sources below:

    https://www.reddit.com/r/Malwarebytes/comments/ie24ui/windows\_defender\_finds\_trojan\_after\_malwarebytes/g2dtgj0/

    https://www.reddit.com/r/Windows10/comments/ipzxeq/what\_is\_trojanwin32dorvdrfn\_and\_why\_is\_it\_always/

    https://www.bleepingcomputer.com/forums/t/728843/win32dorvdrfn-found-by-defender-but-it-cant-delete-it/

    https://sourceforge.net/p/refind/discussion/general/thread/fcf4572b47/?limit=25#3fa9

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2020-09-14T11:16:32+00:00

    Thank You.

    It was great help

    Was this answer helpful?

    0 comments No comments