GlenProuty:
This issue has affected me also. The code is detected but you cannot delete it except by following the manual deletion process you describe. But after removing the files, a successive scan produced a clean system.
Thanks,
Mike
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Since the implementation of W10 V2004, Windows Defender has now been defaulted to identify
PUPS as a threat. As a result, many are now made aware of their presence. And they are "remediated",
on the spot, to prevent them from causing any mischief.
The problem occurs on the subsequent scans with Windows Defender. It identifies the same PUP again,
and again. It has been determined that this is caused by the presence of the PUP in Protection History.
It appears that the default remediation that Windows Defender applies to PUPs is to Block them,
then leave them in Protection History .
EDIT: It has been found that malware other than PUPS, can require this same procedure.
Some have discovered, that even Trojans exhibit this same characteristic, when remediated by
Windows Defender in W10 v2004.
If you have any malware, remediated by Windows Defender, that alerts repeatedly, this procedure applies to
it as well. In order to cleanup the malware completely, find the file in the "container file" in the Protection
History record, and delete the file that is described. If you can't find or access the file, run the Microsoft
Safety Scanner. It uses the same definitions as Windows Defender, and should remediate the file.
Then proceed to delete the Protection History info.
END EDIT.
Windows Defender is defaulted to scan its own "Scans/History". Resulting in the discovery of the malware over
and over again. Even though, other scanners see no evidence of the malware on the PC. It doesn't exist!
Until Microsoft sees fit to fix this problem, you can prevent the repeating error indication, by deleting the
items that are described in Windows Defender Protection History. You can delete them by accessing their files,
that are located in C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service.
In the "Service" folder, find and delete "Detection History".
Note: ProgramData is a hidden file. In order to access it, the "Hidden Items" option in "File Explorer" must be
checked. Find the "Hidden Items" check box under the "View Tab".
And, the first time that you access "Scans", you must select "continue", to obtain the permission.
Restart and try another scan. Notifications for the current malware should stop.
However, this program miscue will probably reoccur, when the next PUP / Malware is encountered.
Glen
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
GlenProuty:
This issue has affected me also. The code is detected but you cannot delete it except by following the manual deletion process you describe. But after removing the files, a successive scan produced a clean system.
Thanks,
Mike
when i type C:\Program Data\Microsoft\Windows Defender\Scans\History\Service. there no match i already click the hidden item , and when i go to powershell admin and type
$Preferences = Get-MpPreference <enter>
$Preferences.ExclusionPath <enter>
this what show up
At line:1 char:37
+ ~
The '<' operator is reserved for future use.
At line:3 char:32
+ ~
The '<' operator is reserved for future use.
+ FullyQualifiedErrorId : RedirectionNotSupported
any sugeestion ?
I happened to get the PUA malware, I looked on multiple forms from Microsoft for help. Windows defender removed it but, it kept showing up like for everyone else. Thus, I did what was recommend on the forms. I downloaded Malwarebytes for free and scanned nothing was found. Same with a Microsoft safety scan (a different program) no threats on full scan. I also did the windows PowerShell admin steps instead of waiting a day after limiting the protection history to 1 day. I did the following, I cleared it by going into program data all the way to detection history by following the thread. I couldn't find any file that said PUA or PUPs so I deleted all of the files in detection history then looked at the protection history again and it was gone. I also full scanned after and it fixed no longer are the same threats appearing. It is indeed a problem with windows defender protection history. I suggest deleting the files inside detection history. It is indeed a problem with windows defender protection history. I'm on the latest updates. IF THE THREAT IS SHOWING ON MALWARBYTES OR WINDOWS SAFETY SCAN STILL MY SOLUTION MIGHT NOT WORK FOR ME WINDOWS DID ITS JOB BUT, KEPT SHOWING THE THREAT AFTER SCANS ON WINDOWS DEFENDER.
Hello again, qweasds
What do you mean by "no match". **>**OS (C:) **>**Program Data **>**Microsoft **>**Windows Defender
**>**Scans **>**History **>**Service is a legitimate location in W10. Try to "navigate" that branch again.
You do not type that location. You open File Explorer and click the > that is just left of each
of the items, to navigate to "Service". Then click "Service" to reveal its contents. Your PUP
(PUA), should be in "Detection History".
If You don't see "Program Data" after you click on the > that is left of OS (C:), you must click
on the VIEW tab at the top of the screen. Then click the block for "Hidden Items" to "check" it.
Close File Explorer, then open it again. You should now be able to see "Program Data".
Good luck, Glen
i did it and there no pua found but when i quick scan it say no new threat found ( does it mean like there threat ? ) but window defender say 0 current threath how to fix it ? when i see the history it epic game launcher/rockstar launcher but you know its ( i delete the gta 5 and still same )
how to fix it