Windows Defender Identifies The SAME PUP As A Threat Repeatedly

Anonymous
2020-06-16T21:00:07+00:00

Since the implementation of W10 V2004, Windows Defender has now been defaulted to identify

PUPS as a threat.  As a result, many are now made aware of their presence.  And they are "remediated",

on the spot, to prevent them from causing any mischief.

The problem occurs on the subsequent scans with Windows Defender. It identifies the same PUP again,

and again. It has been determined that this is caused by the presence of the PUP in Protection History.

It appears that the default remediation that Windows Defender applies to PUPs is to Block them,

then leave them in Protection History .

EDIT:  It has been found that malware other than PUPS, can require this same procedure.

           Some have discovered, that even Trojans exhibit this same characteristic, when remediated by

          Windows Defender in W10 v2004.

If you have any malware, remediated by Windows Defender, that alerts repeatedly, this procedure applies to

it as well. In order to cleanup the malware completely, find the file in the "container file" in the Protection

History record, and delete the file that is described. If you can't find or access the file, run the Microsoft

Safety Scanner. It uses the same definitions as Windows Defender, and should remediate  the file.

https://docs.microsoft.com/en-us/windows/security/threat-protection/intelligence/safety-scanner-download 

Then proceed to delete the Protection History info.

END EDIT.

Windows Defender is defaulted to scan its own "Scans/History". Resulting in the discovery of the malware over

and over again.  Even though, other scanners see no evidence of the malware on the PC.       It doesn't exist!

Until Microsoft sees fit to fix this problem,  you can prevent the repeating error indication, by deleting the

items that are described in Windows Defender Protection History. You can delete them by accessing their files,

that are located in C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service.

In the "Service" folder, find and delete "Detection History"

Note:  ProgramData is a hidden file. In order to access it, the "Hidden Items" option in "File Explorer" must be

checked.  Find the "Hidden Items" check box under the "View Tab".

And, the first time that you access "Scans", you must select "continue", to obtain the permission.

Restart and try another scan.    Notifications for the current malware should stop.  

However, this program miscue will probably reoccur, when the next PUP / Malware is encountered.  

Glen

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

188 answers

Sort by: Most helpful
  1. Anonymous
    2020-06-28T09:05:28+00:00

    Well thanks to your edit. I am now able to find the program data folder. If I delete all the files and folder under the service tab will it work or will i be having any other trouble? Because I cant understand which file is for the PUP.

    Was this answer helpful?

    20+ people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2020-06-29T10:25:14+00:00

    Thanks a lot man. I was going to reinstall windows but your help saved me.

    Thanks again.

    Vibhor

    Was this answer helpful?

    10+ people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2021-08-26T20:50:29+00:00

    Hi James,

    Deleting the contents of Detection History has nothing to do with releasing malware from

    quarantine.

    If you have some concern, that malware that was detected by Defender, was not properly

    remediated, you should download a copy of the Microsoft Safety Scanner, and use it to

    scan your PC. The Scanner and Defender both use the same intelligence definitions.

    Anything that Defender detected, should also be detected and remediated by the Safety

    Scanner, if it has not already been completely remediated by Defender.

    https://docs.microsoft.com/en-us/windows/security/threat-protection/intelligence/safety-scanner-download

    Glen

    Was this answer helpful?

    10 people found this answer helpful.
    0 comments No comments
  4. Anonymous
    2020-08-02T06:11:08+00:00

    hey man thanks for the solution. It really WORKED. After trying too many internet tutorial like Updating windows 10, running sfc scan and many more finally your method worked.

    Here's what i get know about this situation.

    1. The threat is no longer available at the file location because its already deleted.
    2. Windows defender has recorded the threat in history and popping it again and again.
    3. Simply just ignore the notification as the threat is no longer exist or remove it by following the steps below.

    Go to C:\Program Data\Microsoft\Windows Defender\Scans\History\Service and delete all the files reside in it.

    No matter what file you see the defender will automatically recreate the correct files and the PUA notification will be gone forever.

    I usually don't reply to comments but you really helped me, so i am replying back.

    Thanks man, you are a real champ.

    Was this answer helpful?

    10 people found this answer helpful.
    0 comments No comments
  5. Anonymous
    2020-07-05T20:48:40+00:00

    Glen, 

    You sir, are a national treasure. 

    I too had the same issue and after 2 hours of trawling through the internet I found your older thread. I followed this to here and can I just say it. 

    You are the man!!

    Was this answer helpful?

    10 people found this answer helpful.
    0 comments No comments