Windows Defender Identifies The SAME PUP As A Threat Repeatedly

Anonymous
2020-06-16T21:00:07+00:00

Since the implementation of W10 V2004, Windows Defender has now been defaulted to identify

PUPS as a threat.  As a result, many are now made aware of their presence.  And they are "remediated",

on the spot, to prevent them from causing any mischief.

The problem occurs on the subsequent scans with Windows Defender. It identifies the same PUP again,

and again. It has been determined that this is caused by the presence of the PUP in Protection History.

It appears that the default remediation that Windows Defender applies to PUPs is to Block them,

then leave them in Protection History .

EDIT:  It has been found that malware other than PUPS, can require this same procedure.

           Some have discovered, that even Trojans exhibit this same characteristic, when remediated by

          Windows Defender in W10 v2004.

If you have any malware, remediated by Windows Defender, that alerts repeatedly, this procedure applies to

it as well. In order to cleanup the malware completely, find the file in the "container file" in the Protection

History record, and delete the file that is described. If you can't find or access the file, run the Microsoft

Safety Scanner. It uses the same definitions as Windows Defender, and should remediate  the file.

https://docs.microsoft.com/en-us/windows/security/threat-protection/intelligence/safety-scanner-download 

Then proceed to delete the Protection History info.

END EDIT.

Windows Defender is defaulted to scan its own "Scans/History". Resulting in the discovery of the malware over

and over again.  Even though, other scanners see no evidence of the malware on the PC.       It doesn't exist!

Until Microsoft sees fit to fix this problem,  you can prevent the repeating error indication, by deleting the

items that are described in Windows Defender Protection History. You can delete them by accessing their files,

that are located in C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service.

In the "Service" folder, find and delete "Detection History"

Note:  ProgramData is a hidden file. In order to access it, the "Hidden Items" option in "File Explorer" must be

checked.  Find the "Hidden Items" check box under the "View Tab".

And, the first time that you access "Scans", you must select "continue", to obtain the permission.

Restart and try another scan.    Notifications for the current malware should stop.  

However, this program miscue will probably reoccur, when the next PUP / Malware is encountered.  

Glen

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

188 answers

Sort by: Most helpful
  1. Anonymous
    2020-07-16T06:58:22+00:00

    I happened to get the PUA malware, I looked on multiple forms from Microsoft for help. Windows defender removed it but, it kept showing up like for everyone else. Thus, I did what was recommend on the forms. I downloaded Malwarebytes for free and scanned nothing was found. Same with a Microsoft safety scan (a different program) no threats on full scan. I also did the windows PowerShell admin steps instead of waiting a day after limiting the protection history to 1 day. I did the following, I cleared it by going into program data all the way to detection history by following the thread. I couldn't find any file that said PUA or PUPs so I deleted all of the files in detection history then looked at the protection history again and it was gone. I also full scanned after and it fixed no longer are the same threats appearing. It is indeed a problem with windows defender protection history. I suggest deleting the files inside detection history. It is indeed a problem with windows defender protection history. I'm on the latest updates. IF THE THREAT IS SHOWING ON MALWARBYTES OR WINDOWS SAFETY SCAN STILL MY SOLUTION MIGHT NOT WORK FOR ME WINDOWS DID ITS JOB BUT, KEPT SHOWING THE THREAT AFTER SCANS ON WINDOWS DEFENDER.

    Was this answer helpful?

    4 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2020-08-25T20:12:34+00:00

    Hi jodiecooper1,

    To eliminate the alerts from Windows Defender, go back and see the first page of this

    discussion. Therein, it describes the procedure for deleting "Detection History".

    Once that you do that, the alerts will stop.

    Glen

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2020-08-13T22:47:50+00:00

    thanks glen, it worked like a charm =)

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  4. Monkey57 3,535 Reputation points
    2020-07-20T15:29:07+00:00

    GlenProuty,

    "Since the implementation of W10 V2004, Windows Defender has now been defaulted to identify

    PUPS as a threat."-> To me this is very exciting news (although I acknowledge I have not read thru this entire thread)..

    In the past I have recommended and set my clients to turn on PUP (PUA) protection within Windows Defender.

    Greg's answermarked suggestion in the following thread 'to turn ON PUP' protection is a featured favorite on my browser toolbar:

    https://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning-windows_10/windows-defender-not-detecting-known-adware/9cfe114b-8d1b-42a2-8268-34dc3acf9390?auth=1

    I acknowledge it has picked up some of my "tools" and wacked them out, it was not hard to set up exceptions. (I have backups and know how to recover the "tools" not fit for general usage).

    If you want to revert to a less protected state, consider reversing the PUA setting.

    Monkey57

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  5. Anonymous
    2020-07-15T17:19:51+00:00

    GlenProuty:

    This issue has affected me also. The code is detected but you cannot delete it except by following the manual deletion process you describe. But after removing the files, a successive scan produced a clean system.

    Thanks,

    Mike

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments