I happened to get the PUA malware, I looked on multiple forms from Microsoft for help. Windows defender removed it but, it kept showing up like for everyone else. Thus, I did what was recommend on the forms. I downloaded Malwarebytes for free and scanned nothing was found. Same with a Microsoft safety scan (a different program) no threats on full scan. I also did the windows PowerShell admin steps instead of waiting a day after limiting the protection history to 1 day. I did the following, I cleared it by going into program data all the way to detection history by following the thread. I couldn't find any file that said PUA or PUPs so I deleted all of the files in detection history then looked at the protection history again and it was gone. I also full scanned after and it fixed no longer are the same threats appearing. It is indeed a problem with windows defender protection history. I suggest deleting the files inside detection history. It is indeed a problem with windows defender protection history. I'm on the latest updates. IF THE THREAT IS SHOWING ON MALWARBYTES OR WINDOWS SAFETY SCAN STILL MY SOLUTION MIGHT NOT WORK FOR ME WINDOWS DID ITS JOB BUT, KEPT SHOWING THE THREAT AFTER SCANS ON WINDOWS DEFENDER.
Windows Defender Identifies The SAME PUP As A Threat Repeatedly
Since the implementation of W10 V2004, Windows Defender has now been defaulted to identify
PUPS as a threat. As a result, many are now made aware of their presence. And they are "remediated",
on the spot, to prevent them from causing any mischief.
The problem occurs on the subsequent scans with Windows Defender. It identifies the same PUP again,
and again. It has been determined that this is caused by the presence of the PUP in Protection History.
It appears that the default remediation that Windows Defender applies to PUPs is to Block them,
then leave them in Protection History .
EDIT: It has been found that malware other than PUPS, can require this same procedure.
Some have discovered, that even Trojans exhibit this same characteristic, when remediated by
Windows Defender in W10 v2004.
If you have any malware, remediated by Windows Defender, that alerts repeatedly, this procedure applies to
it as well. In order to cleanup the malware completely, find the file in the "container file" in the Protection
History record, and delete the file that is described. If you can't find or access the file, run the Microsoft
Safety Scanner. It uses the same definitions as Windows Defender, and should remediate the file.
Then proceed to delete the Protection History info.
END EDIT.
Windows Defender is defaulted to scan its own "Scans/History". Resulting in the discovery of the malware over
and over again. Even though, other scanners see no evidence of the malware on the PC. It doesn't exist!
Until Microsoft sees fit to fix this problem, you can prevent the repeating error indication, by deleting the
items that are described in Windows Defender Protection History. You can delete them by accessing their files,
that are located in C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service.
In the "Service" folder, find and delete "Detection History".
Note: ProgramData is a hidden file. In order to access it, the "Hidden Items" option in "File Explorer" must be
checked. Find the "Hidden Items" check box under the "View Tab".
And, the first time that you access "Scans", you must select "continue", to obtain the permission.
Restart and try another scan. Notifications for the current malware should stop.
However, this program miscue will probably reoccur, when the next PUP / Malware is encountered.
Glen
Windows for home | Windows 10 | Security and privacy
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
188 answers
Sort by: Newest
-
Anonymous
2020-07-16T06:58:22+00:00 -
Anonymous
2020-07-16T06:43:28+00:00 when i type C:\Program Data\Microsoft\Windows Defender\Scans\History\Service. there no match i already click the hidden item , and when i go to powershell admin and type
$Preferences = Get-MpPreference <enter>
$Preferences.ExclusionPath <enter>
this what show up
At line:1 char:37
- $Preferences = Get-MpPreference <enter>
+ ~
The '<' operator is reserved for future use.
At line:3 char:32
- $Preferences.ExclusionPath <enter>
+ ~
The '<' operator is reserved for future use.
- CategoryInfo : ParserError: (:) [], ParentContainsErrorRecordException
+ FullyQualifiedErrorId : RedirectionNotSupported
any sugeestion ?
-
Anonymous
2020-07-15T17:19:51+00:00 GlenProuty:
This issue has affected me also. The code is detected but you cannot delete it except by following the manual deletion process you describe. But after removing the files, a successive scan produced a clean system.
Thanks,
Mike
-
Anonymous
2020-07-13T23:45:45+00:00 Hi qweasds,
If Microsoft Scanner and MalwareBytes do not show any malware threats, PUP
or otherwise, your PC is not threatened. The repeating notification that you get,
identifying a PUP, is a program error in W10 v2004. Nothing more!
If you are getting a the repeating notification of a PUA, as shown in Protection
History, that is the result of the program error! Your PC is not threatened. You
can eliminate the annoying notification, by following my instructions on the first
page of this thread.
Regarding (F2royr.exe or F2roy.exe), I find no information that identifies this as
as anything. Examine the record in Protection History for your repeating notification,
and find the name of your PUP. (PUA something). Find that in the location that is
described on page one of this thread, and delete it. That will stop the notifications.
Glen
-
Anonymous
2020-07-13T22:36:22+00:00 glen
I just wondering, if i not remove the copy of the threat that you recomend is my computer still safe ?