"Detection History" klasörünü komple sildim. Sonra Defender ile tarattım. Sonuç aşağıda. Üzgünüm sonuç olumsuz.
Windows Defender Identifies The SAME PUP As A Threat Repeatedly
Since the implementation of W10 V2004, Windows Defender has now been defaulted to identify
PUPS as a threat. As a result, many are now made aware of their presence. And they are "remediated",
on the spot, to prevent them from causing any mischief.
The problem occurs on the subsequent scans with Windows Defender. It identifies the same PUP again,
and again. It has been determined that this is caused by the presence of the PUP in Protection History.
It appears that the default remediation that Windows Defender applies to PUPs is to Block them,
then leave them in Protection History .
EDIT: It has been found that malware other than PUPS, can require this same procedure.
Some have discovered, that even Trojans exhibit this same characteristic, when remediated by
Windows Defender in W10 v2004.
If you have any malware, remediated by Windows Defender, that alerts repeatedly, this procedure applies to
it as well. In order to cleanup the malware completely, find the file in the "container file" in the Protection
History record, and delete the file that is described. If you can't find or access the file, run the Microsoft
Safety Scanner. It uses the same definitions as Windows Defender, and should remediate the file.
Then proceed to delete the Protection History info.
END EDIT.
Windows Defender is defaulted to scan its own "Scans/History". Resulting in the discovery of the malware over
and over again. Even though, other scanners see no evidence of the malware on the PC. It doesn't exist!
Until Microsoft sees fit to fix this problem, you can prevent the repeating error indication, by deleting the
items that are described in Windows Defender Protection History. You can delete them by accessing their files,
that are located in C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service.
In the "Service" folder, find and delete "Detection History".
Note: ProgramData is a hidden file. In order to access it, the "Hidden Items" option in "File Explorer" must be
checked. Find the "Hidden Items" check box under the "View Tab".
And, the first time that you access "Scans", you must select "continue", to obtain the permission.
Restart and try another scan. Notifications for the current malware should stop.
However, this program miscue will probably reoccur, when the next PUP / Malware is encountered.
Glen
Windows for home | Windows 10 | Security and privacy
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
188 answers
Sort by: Oldest
-
Anonymous
2020-09-06T09:47:48+00:00 -
Anonymous
2020-09-06T14:26:05+00:00 I have no idea. Unfortunately, it is not what I understand. All I want is to get rid of this trojan without formatting. I haven't achieved this yet.
-
Anonymous
2020-09-06T14:33:53+00:00 this is not working for me. I did this:
Go to C:\Program Data\Microsoft\Windows Defender\Scans\History\Service and delete all the files reside in it.
finds it again every time. and it can't take any action.
-
Anonymous
2020-09-06T22:01:12+00:00 Hi Yunus,
In the notification in Protection History, there should be a "Container File", with the
location of the malware described. Go to that location and delete the malware.
Then delete the Detection History using the same procedure as before.
Glen
-
Anonymous
2020-09-07T01:58:37+00:00 Hi Yunus,
If you have a problem finding the Trojan file, you should be able to remediate it by
downloading a copy of Microsoft Safety Scanner, and running a full scan. It uses the
same definitions as Defender, which has detected this Trojan since 2017.
After running the Safety Scanner, you should then delete the Detection History, as previously
described. This will eliminate the false positive produced by Protection History.
Good luck, Glen