So deleting detection history won't release the virus from quarantine? Cos I'm scared as I'm just facing the same issue and the threat turns out to be severe.
Windows Defender Identifies The SAME PUP As A Threat Repeatedly
Since the implementation of W10 V2004, Windows Defender has now been defaulted to identify
PUPS as a threat. As a result, many are now made aware of their presence. And they are "remediated",
on the spot, to prevent them from causing any mischief.
The problem occurs on the subsequent scans with Windows Defender. It identifies the same PUP again,
and again. It has been determined that this is caused by the presence of the PUP in Protection History.
It appears that the default remediation that Windows Defender applies to PUPs is to Block them,
then leave them in Protection History .
EDIT: It has been found that malware other than PUPS, can require this same procedure.
Some have discovered, that even Trojans exhibit this same characteristic, when remediated by
Windows Defender in W10 v2004.
If you have any malware, remediated by Windows Defender, that alerts repeatedly, this procedure applies to
it as well. In order to cleanup the malware completely, find the file in the "container file" in the Protection
History record, and delete the file that is described. If you can't find or access the file, run the Microsoft
Safety Scanner. It uses the same definitions as Windows Defender, and should remediate the file.
Then proceed to delete the Protection History info.
END EDIT.
Windows Defender is defaulted to scan its own "Scans/History". Resulting in the discovery of the malware over
and over again. Even though, other scanners see no evidence of the malware on the PC. It doesn't exist!
Until Microsoft sees fit to fix this problem, you can prevent the repeating error indication, by deleting the
items that are described in Windows Defender Protection History. You can delete them by accessing their files,
that are located in C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service.
In the "Service" folder, find and delete "Detection History".
Note: ProgramData is a hidden file. In order to access it, the "Hidden Items" option in "File Explorer" must be
checked. Find the "Hidden Items" check box under the "View Tab".
And, the first time that you access "Scans", you must select "continue", to obtain the permission.
Restart and try another scan. Notifications for the current malware should stop.
However, this program miscue will probably reoccur, when the next PUP / Malware is encountered.
Glen
Windows for home | Windows 10 | Security and privacy
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
188 answers
Sort by: Most helpful
-
Anonymous
2021-08-26T18:02:14+00:00 -
Anonymous
2020-12-24T14:59:02+00:00 I’ve been having the same problem with what I thought was a false positive trojan over the last couple of days but until today I didn’t know there was a fix for it, I chose not to download the safety scanner just yet but took the steps you described about deleting the defender history, I am doing a full scan now after restarting my laptop and I presume you’d recommend I do get the safety scanner if this does reoccur again?, I will let you know if the scan produces the trojan once more.
It turns out that it was not a false positive and I've had several detections which I have removed, all stemming from the same folder associated with Discord, I have now deleted the app from my laptop and from here on I'll be using it on the internet, if I get one more trojan notification I might get rid of it completely but its just a wait and see thing now.
-
Anonymous
2020-10-04T12:15:17+00:00 hey its nice that you helped me thank you soo much
-
Anonymous
2020-07-26T16:39:05+00:00 Glen, thank you for your advice. Just as others, I spent hours trying to get rid of the "PUA:Win32/InstallCore" notification that kept showing up as an "Active" threat in Windows Defender despite WD also saying that "no threats were found" after running several scans on my PC. I had downloaded and ran several other anti-virus programs (trial versions) too and nothing was found. I already have Malwarebytes and the program was also finding nothing. All was a mystery and frustrating ordeal until I found this post. I followed your instructions and simply deleted the files in the Detection History and that solved the problem. Unbelievable. BIG THANKS to you again for your help with this issue!
-
Anonymous
2020-07-13T22:07:50+00:00 Hi Joe,
I am afraid that I do not understand your post. If you have major damage in your
system, it is probably not caused by a PUP.
In your case you should download a free copy of MalwareBytes and run a full scan
of your PC, if you can. Set it to "scan for rootkits" first. Quarantine all that it finds.
If necessary, boot into Safe Mode first, then run the scan.
The Windows Defender Offline scan is another good choice. Since it runs outside
the confines of the operating system, a virus cannot protect itself from detection.
In case your problem, turns out not to be malware, please respond with more symptoms,
and I will be glad to help, if I can.
Good luck, Glen