this is not working for me. I did this:
Go to C:\Program Data\Microsoft\Windows Defender\Scans\History\Service and delete all the files reside in it.
finds it again every time. and it can't take any action.
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Since the implementation of W10 V2004, Windows Defender has now been defaulted to identify
PUPS as a threat. As a result, many are now made aware of their presence. And they are "remediated",
on the spot, to prevent them from causing any mischief.
The problem occurs on the subsequent scans with Windows Defender. It identifies the same PUP again,
and again. It has been determined that this is caused by the presence of the PUP in Protection History.
It appears that the default remediation that Windows Defender applies to PUPs is to Block them,
then leave them in Protection History .
EDIT: It has been found that malware other than PUPS, can require this same procedure.
Some have discovered, that even Trojans exhibit this same characteristic, when remediated by
Windows Defender in W10 v2004.
If you have any malware, remediated by Windows Defender, that alerts repeatedly, this procedure applies to
it as well. In order to cleanup the malware completely, find the file in the "container file" in the Protection
History record, and delete the file that is described. If you can't find or access the file, run the Microsoft
Safety Scanner. It uses the same definitions as Windows Defender, and should remediate the file.
Then proceed to delete the Protection History info.
END EDIT.
Windows Defender is defaulted to scan its own "Scans/History". Resulting in the discovery of the malware over
and over again. Even though, other scanners see no evidence of the malware on the PC. It doesn't exist!
Until Microsoft sees fit to fix this problem, you can prevent the repeating error indication, by deleting the
items that are described in Windows Defender Protection History. You can delete them by accessing their files,
that are located in C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service.
In the "Service" folder, find and delete "Detection History".
Note: ProgramData is a hidden file. In order to access it, the "Hidden Items" option in "File Explorer" must be
checked. Find the "Hidden Items" check box under the "View Tab".
And, the first time that you access "Scans", you must select "continue", to obtain the permission.
Restart and try another scan. Notifications for the current malware should stop.
However, this program miscue will probably reoccur, when the next PUP / Malware is encountered.
Glen
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
this is not working for me. I did this:
Go to C:\Program Data\Microsoft\Windows Defender\Scans\History\Service and delete all the files reside in it.
finds it again every time. and it can't take any action.
I have no idea. Unfortunately, it is not what I understand. All I want is to get rid of this trojan without formatting. I haven't achieved this yet.
It seems well and truly gone Glen. Thanks again for your help mate. Cheers
Hi Marcus,
"Piriform Bundler" is considered to be a PUP (PUA) by Microsoft Defender.
Look in Protection History, to see if you have a notification regarding "Piriform
Bundler". Since you say Defender handled it, I suspect that there is no notification.
In that case, Microsoft has fixed the problem that you experienced.
Antimalware Platform v 4.18.2008.9-0 is probably the fix.
I think they now clear Protection History themselves, when you click "TakeAction".
If you care to verify that, you can observe the Event Viewer to see. Navigate through
Event Viewer >Applications and Services Logs>Microsoft>Windows>Windows Defender>Operational.
In the right pane, under "Actions", click "Filter Current Log". In the panel that appears,
type 1116,1117 where it says <All Event IDs>, and click OK.
In the Event Log, only event 1116 & 1117 logs will appear. If you observe the log's "Properties",
you will see that the malware was cleared.
In the right pane click "Clear Filter", then exit the Event Viewer.
Best of luck to you, Glen