Windows Defender Identifies The SAME PUP As A Threat Repeatedly

Anonymous
2020-06-16T21:00:07+00:00

Since the implementation of W10 V2004, Windows Defender has now been defaulted to identify

PUPS as a threat.  As a result, many are now made aware of their presence.  And they are "remediated",

on the spot, to prevent them from causing any mischief.

The problem occurs on the subsequent scans with Windows Defender. It identifies the same PUP again,

and again. It has been determined that this is caused by the presence of the PUP in Protection History.

It appears that the default remediation that Windows Defender applies to PUPs is to Block them,

then leave them in Protection History .

EDIT:  It has been found that malware other than PUPS, can require this same procedure.

           Some have discovered, that even Trojans exhibit this same characteristic, when remediated by

          Windows Defender in W10 v2004.

If you have any malware, remediated by Windows Defender, that alerts repeatedly, this procedure applies to

it as well. In order to cleanup the malware completely, find the file in the "container file" in the Protection

History record, and delete the file that is described. If you can't find or access the file, run the Microsoft

Safety Scanner. It uses the same definitions as Windows Defender, and should remediate  the file.

https://docs.microsoft.com/en-us/windows/security/threat-protection/intelligence/safety-scanner-download 

Then proceed to delete the Protection History info.

END EDIT.

Windows Defender is defaulted to scan its own "Scans/History". Resulting in the discovery of the malware over

and over again.  Even though, other scanners see no evidence of the malware on the PC.       It doesn't exist!

Until Microsoft sees fit to fix this problem,  you can prevent the repeating error indication, by deleting the

items that are described in Windows Defender Protection History. You can delete them by accessing their files,

that are located in C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service.

In the "Service" folder, find and delete "Detection History"

Note:  ProgramData is a hidden file. In order to access it, the "Hidden Items" option in "File Explorer" must be

checked.  Find the "Hidden Items" check box under the "View Tab".

And, the first time that you access "Scans", you must select "continue", to obtain the permission.

Restart and try another scan.    Notifications for the current malware should stop.  

However, this program miscue will probably reoccur, when the next PUP / Malware is encountered.  

Glen

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

188 answers

Sort by: Most helpful
  1. Anonymous
    2020-09-23T09:41:58+00:00

    Sir, I am not able to open "Scans". It's not expanding. I am repeatedly clicking on it but it is not opening. I have clicked on it a thousand times but it's not opening, Sir.

    I request you to please help me!!

    If you want I can mail you the screenshot or the screen recording.

    Or you can create a meeting on meet to help me resolve this issue live.

    Thank you, Sir!!

    I am really irritating you, Sir. But that issue is irritating me too.

    Thank you very much Sir!! for all the help till now. Just help me this last time.

    Hopeful, Labeeb.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  2. Anonymous
    2020-09-10T04:11:40+00:00

    Glen is a great advisor here

    I also had the same experience with Yunus on multiple PCs

    Microsoft Defender must be stopped to resolve the issue.

    Solution

    I have installed other security vendors and left Defender's real-time protection disabled, then

    I even deleted C: \ ProgramData \ Microsoft \ Windows Defender \ Scans \ History \ Results.

    I have to try this, uninstalling another security vendor and enabling Microsoft Defender. Free upgrade of Windows 10 may leave device security and multiple issues in your system.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  3. Anonymous
    2020-09-07T01:58:37+00:00

    Hi Yunus,

    If you have a problem finding the Trojan file, you should be able to remediate it by

    downloading a copy of Microsoft Safety Scanner, and running a full scan. It uses the

    same definitions as Defender, which has detected this Trojan since 2017.

    https://docs.microsoft.com/en-us/windows/security/threat-protection/intelligence/safety-scanner-download

    After running the Safety Scanner, you should then delete the Detection History, as previously

    described. This will eliminate the false positive produced by Protection History.

    Good luck,  Glen

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  4. Anonymous
    2020-09-05T08:25:37+00:00

    Hi Marcus,

    "Piriform Bundler" is considered to be a PUP (PUA) by Microsoft Defender.

    Look in Protection History, to see if you have a notification regarding "Piriform

    Bundler".  Since you say Defender handled it, I suspect that there is no notification.

    In that case, Microsoft has fixed the problem that you experienced.

    Antimalware Platform v 4.18.2008.9-0 is probably the fix.

    I think they now clear Protection History themselves, when you click "TakeAction".

    If you care to verify that, you can observe the Event Viewer to see. Navigate through

    Event Viewer >Applications and Services Logs>Microsoft>Windows>Windows Defender>Operational.

    In the right pane, under "Actions", click "Filter Current Log". In the panel that appears,

    type 1116,1117 where it says <All Event IDs>, and click OK.

    In the Event Log, only event 1116 & 1117 logs will appear. If you observe the log's "Properties",

    you will see that the malware was cleared.

    In the right pane click "Clear Filter", then exit the Event Viewer.

    Best of luck to you,  Glen

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  5. Anonymous
    2020-09-04T20:29:47+00:00

    Hi Joanne,

    Microsoft has taken an action to correct this software shortcoming in v2004.

    They have provided a provision in Platform v4.18.2008.9-0 that cleans up Protection

    History, when you take "Action" on the PUP.

    You can see this occur in the Event Viewer. Filter for event 1117. In Applications and

    Services Logs\Microsoft\Windows\Windows Defender\Operational.

    There is no need to delete the Detection History folder anymore.

    Regards,  Glen

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments