Windows Defender Identifies The SAME PUP As A Threat Repeatedly

Anonymous
2020-06-16T21:00:07+00:00

Since the implementation of W10 V2004, Windows Defender has now been defaulted to identify

PUPS as a threat.  As a result, many are now made aware of their presence.  And they are "remediated",

on the spot, to prevent them from causing any mischief.

The problem occurs on the subsequent scans with Windows Defender. It identifies the same PUP again,

and again. It has been determined that this is caused by the presence of the PUP in Protection History.

It appears that the default remediation that Windows Defender applies to PUPs is to Block them,

then leave them in Protection History .

EDIT:  It has been found that malware other than PUPS, can require this same procedure.

           Some have discovered, that even Trojans exhibit this same characteristic, when remediated by

          Windows Defender in W10 v2004.

If you have any malware, remediated by Windows Defender, that alerts repeatedly, this procedure applies to

it as well. In order to cleanup the malware completely, find the file in the "container file" in the Protection

History record, and delete the file that is described. If you can't find or access the file, run the Microsoft

Safety Scanner. It uses the same definitions as Windows Defender, and should remediate  the file.

https://docs.microsoft.com/en-us/windows/security/threat-protection/intelligence/safety-scanner-download 

Then proceed to delete the Protection History info.

END EDIT.

Windows Defender is defaulted to scan its own "Scans/History". Resulting in the discovery of the malware over

and over again.  Even though, other scanners see no evidence of the malware on the PC.       It doesn't exist!

Until Microsoft sees fit to fix this problem,  you can prevent the repeating error indication, by deleting the

items that are described in Windows Defender Protection History. You can delete them by accessing their files,

that are located in C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service.

In the "Service" folder, find and delete "Detection History"

Note:  ProgramData is a hidden file. In order to access it, the "Hidden Items" option in "File Explorer" must be

checked.  Find the "Hidden Items" check box under the "View Tab".

And, the first time that you access "Scans", you must select "continue", to obtain the permission.

Restart and try another scan.    Notifications for the current malware should stop.  

However, this program miscue will probably reoccur, when the next PUP / Malware is encountered.  

Glen

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

188 answers

Sort by: Oldest
  1. Anonymous
    2021-03-14T21:07:46+00:00

    Hi Glen, bit late on the case, I've just realised/discovered that I am getting the same Defender warning because of the history folder! Have just run the Safety Scanner, deleted Detection History, Restarted, Run Defender Full Scan, and got no PUAs. Thank you! Mike.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2021-05-04T13:27:15+00:00

    Hi Glen

    Thanks for posting your very helpful article, I wonder if you can cast some light on my situation that is similar?

    I noticed that Defender has started to show a threat found as below.

     

    In notifications it says that threats have been found and action taken, yet Protection history as below shows no recent actions.

     

    Deleting the logs in C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service followed by a restart does not fix the problem, the scan continues to find a threat.

    My windows is:

    So I have tried the Microsoft Safety scanner with the results depicted blow:

    As you can see it appears to find 5 infections, yet when it completes it states none found.

    This is the extract from MSERT.LOG file for the scan


    Microsoft Safety Scanner v1.337, (build 1.337.521.0)

    Started On Tue May  4 10:10:08 2021

    Engine: 1.1.18100.5

    Signatures: 1.337.521.0

    MpGear: 1.1.16330.1

    Run Mode: Interactive Graphical Mode

    Results Summary:


    No infection found.

    Successfully Submitted MAPS Report

    Successfully Submitted Heartbeat Report

    Microsoft Safety Scanner Finished On Tue May  4 12:32:12 2021

    Return code: 0 (0x0)

    I have tried downloading and running the current version of Malwarebytes and it finds no problems, so I’m tempted to believe that the threats are false positives, but cannot identify them.

    Your thoughts an suggestions would be appreciated.

    Thanks

    Andrew

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2021-05-04T20:32:23+00:00

    Hi Andrew,

    I believe that your assessment, that it is a false positive, is accurate.

    See Rob's answer in this thread, regarding what you are experiencing with the Safety Scanner.

    https://answers.microsoft.com/en-us/protect/forum/all/what-is-wrong-with-the-microsoft-safety-scanner/27c95df9-7d49-4d02-b734-bcb16495cfc3

    As far as Quick scan saying both, "no current threat" and "1 threat found", that appears to be

    related to the misnomer that the Scanner shows.  Especially since there is nothing in Protection

    History.

    If you can run Defender Offline, without detecting the error, I think you can be assured that it

    is just an anomaly, that may be fixed with subsequent updates.

    Good luck,  Glen

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  4. Anonymous
    2021-05-04T21:28:02+00:00

    Thanks for the response Glen and for the link to Rob Koch's excellent explanation. 

    I had already run the Defender Offline scan a couple of times without detecting any problems, so as you say let's hope a future update to Defender fixes the issue.

    It certainly helps to have an improved understanding of how these things work.

    Best wishes, Andrew

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2021-05-07T16:35:59+00:00

    Since the implementation of W10 V2004, Windows Defender has now been defaulted to identify

    PUPS as a threat.  As a result, many are now made aware of their presence.  And they are "remediated",

    on the spot, to prevent them from causing any mischief.

    The problem occurs on the subsequent scans with Windows Defender. It identifies the same PUP again,

    and again. It has been determined that this is caused by the presence of the PUP in Protection History.

    It appears that the default remediation that Windows Defender applies to PUPs is to Block them,

    then leave them in Protection History .

    EDIT:  It has been found that malware other than PUPS, can require this same procedure.

               Some have discovered, that even Trojans exhibit this same characteristic, when remediated by

              Windows Defender in W10 v2004.

    If you have any malware, remediated by Windows Defender, that alerts repeatedly, this procedure applies to

    it as well. In order to cleanup the malware completely, find the file in the "container file" in the Protection

    History record, and delete the file that is described. If you can't find or access the file, run the Microsoft

    Safety Scanner. It uses the same definitions as Windows Defender, and should remediate  the file.

    https://docs.microsoft.com/en-us/windows/security/threat-protection/intelligence/safety-scanner-download 

    Then proceed to delete the Protection History info.

    END EDIT.

    Windows Defender is defaulted to scan its own "Scans/History". Resulting in the discovery of the malware over

    and over again.  Even though, other scanners see no evidence of the malware on the PC.       It doesn't exist!

    Until Microsoft sees fit to fix this problem,  you can prevent the repeating error indication, by deleting the

    items that are described in Windows Defender Protection History. You can delete them by accessing their files,

    that are located in C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service.

    In the "Service" folder, find and delete "Detection History"

    Note:  ProgramData is a hidden file. In order to access it, the "Hidden Items" option in "File Explorer" must be

    checked.  Find the "Hidden Items" check box under the "View Tab".

    And, the first time that you access "Scans", you must select "continue", to obtain the permission.

    Restart and try another scan.    Notifications for the current malware should stop.  

    However, this program miscue will probably reoccur, when the next PUP / Malware is encountered.  

    Glen 

    Thank you very much for your kind advice. I did it and problems solved.

    Was this answer helpful?

    0 comments No comments