Windows Defender Identifies The SAME PUP As A Threat Repeatedly

Anonymous
2020-06-16T21:00:07+00:00

Since the implementation of W10 V2004, Windows Defender has now been defaulted to identify

PUPS as a threat.  As a result, many are now made aware of their presence.  And they are "remediated",

on the spot, to prevent them from causing any mischief.

The problem occurs on the subsequent scans with Windows Defender. It identifies the same PUP again,

and again. It has been determined that this is caused by the presence of the PUP in Protection History.

It appears that the default remediation that Windows Defender applies to PUPs is to Block them,

then leave them in Protection History .

EDIT:  It has been found that malware other than PUPS, can require this same procedure.

           Some have discovered, that even Trojans exhibit this same characteristic, when remediated by

          Windows Defender in W10 v2004.

If you have any malware, remediated by Windows Defender, that alerts repeatedly, this procedure applies to

it as well. In order to cleanup the malware completely, find the file in the "container file" in the Protection

History record, and delete the file that is described. If you can't find or access the file, run the Microsoft

Safety Scanner. It uses the same definitions as Windows Defender, and should remediate  the file.

https://docs.microsoft.com/en-us/windows/security/threat-protection/intelligence/safety-scanner-download 

Then proceed to delete the Protection History info.

END EDIT.

Windows Defender is defaulted to scan its own "Scans/History". Resulting in the discovery of the malware over

and over again.  Even though, other scanners see no evidence of the malware on the PC.       It doesn't exist!

Until Microsoft sees fit to fix this problem,  you can prevent the repeating error indication, by deleting the

items that are described in Windows Defender Protection History. You can delete them by accessing their files,

that are located in C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service.

In the "Service" folder, find and delete "Detection History"

Note:  ProgramData is a hidden file. In order to access it, the "Hidden Items" option in "File Explorer" must be

checked.  Find the "Hidden Items" check box under the "View Tab".

And, the first time that you access "Scans", you must select "continue", to obtain the permission.

Restart and try another scan.    Notifications for the current malware should stop.  

However, this program miscue will probably reoccur, when the next PUP / Malware is encountered.  

Glen

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

188 answers

Sort by: Oldest
  1. Anonymous
    2020-09-09T23:36:56+00:00

    Glen thanks for your attention,

    But I just couldn't get rid of this problem. 

    I scanned with Microsoft Anti Malware and couldn't find anything

    After that C:\Program Data\Microsoft\Windows Defender\Scans\History\Service and delete all the files reside in it.

    I even deleted C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results. 

    Then scanned with defender. Defender alerted me 

    But couldn't Deleted or Quarantine. 

    this is also interesting; Defender says I found no threat as a result.

    By the way the trojan also says BIOS / UEFI. I don't know how to delete the file from there. But let me investigate.See u
    

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2020-09-10T04:05:22+00:00

    Hi Yunus,

    I am unable to read your screenshots of Protection History, so I don't gather much from them.

    But I have seen your participation in other threads, that do have screenshots that I can read.

    Have you examined **C:\user**(*username)*AppData\Local\Temp\IOC70DB.tmp. From one

    of the threads, I got the impression, that was the location the "Container File" described.

    You could try deleting this file, then see if Defender continued to alert. (After deleting history).

    Since no other Security program detects the item that Defender finds, it would appear to

    be a false positive. Maybe Defender is identifying a component already in Protection History,

    that it considers to be your problem. One would think that you would have eliminated that

    possibility, by deleting all that you did already. But maybe not! It may be stored elsewhere.

    Using Windows PowerShell (Admin) you could purge all of the history, after a one day delay.

    Open PowerShell Admin, and type this Cmdlet.

    Set-MpPreference -ScanPurgeItemsAfterDelay 1     <enter>

    Exit     <enter>

    This will empty all of history, including Quarantined items, after one full day.

    After your test, you should re-run the Cmdlet using 1E  (30 days)

    For what is worth, if you did not see it in the other threads that you visited, An OP declared

    that they solved this problem, by removing a USB drive. One that they always left plugged in.

    Tests on the USB, showed no problems.

    Other OPs declared that this problem began for them, when their free subscription for

    MalwareBytes ran out!!!

    Hopefully, you can solve your problem by some other means, but one OP declared that if

    malware had really attacked your UEFI, you would have to replace your machine!!!

    I can only wish you, Good luck   Glen

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2020-09-10T04:11:40+00:00

    Glen is a great advisor here

    I also had the same experience with Yunus on multiple PCs

    Microsoft Defender must be stopped to resolve the issue.

    Solution

    I have installed other security vendors and left Defender's real-time protection disabled, then

    I even deleted C: \ ProgramData \ Microsoft \ Windows Defender \ Scans \ History \ Results.

    I have to try this, uninstalling another security vendor and enabling Microsoft Defender. Free upgrade of Windows 10 may leave device security and multiple issues in your system.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  4. Anonymous
    2020-09-10T19:23:01+00:00

    So what do I do?

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2020-09-10T20:44:40+00:00

    Defender must be in a stopped state once.

    In that state C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service.

    Delete

    Again  Defender  Enable it.

    Was this answer helpful?

    0 comments No comments