Windows Defender Identifies The SAME PUP As A Threat Repeatedly

Anonymous
2020-06-16T21:00:07+00:00

Since the implementation of W10 V2004, Windows Defender has now been defaulted to identify

PUPS as a threat.  As a result, many are now made aware of their presence.  And they are "remediated",

on the spot, to prevent them from causing any mischief.

The problem occurs on the subsequent scans with Windows Defender. It identifies the same PUP again,

and again. It has been determined that this is caused by the presence of the PUP in Protection History.

It appears that the default remediation that Windows Defender applies to PUPs is to Block them,

then leave them in Protection History .

EDIT:  It has been found that malware other than PUPS, can require this same procedure.

           Some have discovered, that even Trojans exhibit this same characteristic, when remediated by

          Windows Defender in W10 v2004.

If you have any malware, remediated by Windows Defender, that alerts repeatedly, this procedure applies to

it as well. In order to cleanup the malware completely, find the file in the "container file" in the Protection

History record, and delete the file that is described. If you can't find or access the file, run the Microsoft

Safety Scanner. It uses the same definitions as Windows Defender, and should remediate  the file.

https://docs.microsoft.com/en-us/windows/security/threat-protection/intelligence/safety-scanner-download 

Then proceed to delete the Protection History info.

END EDIT.

Windows Defender is defaulted to scan its own "Scans/History". Resulting in the discovery of the malware over

and over again.  Even though, other scanners see no evidence of the malware on the PC.       It doesn't exist!

Until Microsoft sees fit to fix this problem,  you can prevent the repeating error indication, by deleting the

items that are described in Windows Defender Protection History. You can delete them by accessing their files,

that are located in C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service.

In the "Service" folder, find and delete "Detection History"

Note:  ProgramData is a hidden file. In order to access it, the "Hidden Items" option in "File Explorer" must be

checked.  Find the "Hidden Items" check box under the "View Tab".

And, the first time that you access "Scans", you must select "continue", to obtain the permission.

Restart and try another scan.    Notifications for the current malware should stop.  

However, this program miscue will probably reoccur, when the next PUP / Malware is encountered.  

Glen

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

188 answers

Sort by: Most helpful
  1. Anonymous
    2021-01-06T11:08:35+00:00

    Hi Glen,

    i do not get any popup. It just simply won't open the Scan folder

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  2. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  3. Anonymous
    2020-12-20T23:08:05+00:00

    Hi Matt,

    Glad to hear that you have solved your problem.

    I do not have any experience with HitmanPro, although it is recommended for use by

    many sites, for assisting in the removal of stubborn malware.

    MalwareBytes is one of the best "Scanners", to have on hand to use for "on demand"

    scans.  Sometimes, when used as "real-time" protection, it can conflict with Defender.

    Defender is probably the best real-time protection for W10 PCs. Integrated and updated

    by the OS on a regular basis, and requires less resources than the other programs.

    Every program is prone to miss something, now and then . That is why it is a good idea to

    perform an Offline Scan periodically, and use another scanner, for a second opinion occasionally.

    Good luck,  Glen

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  4. Anonymous
    2020-12-19T00:16:17+00:00

    Hi Matt,

    No, you do not need to keep MalwareBytes. However, it is a very good program to

    have around for "on demand" scans. Just turn off all of its "Real-Time" functions. And

    in "Settings" under "Security" >Windows Security Center, turn off "Always register

    MalwareBytes in the Windows Security Center."

    After a restart, Defender should be enabled again. Please reply if it is not.

    Somebody was apparently experiencing difficulties, trying to remove Santivirus

    in normal mode, since they saw it come back.

    If the SantivirusEngine.Dll is still in place, delete it. Use Safe Mode if necessary.

    IF Defender does not re-enable after the changes to MalwareBytes, display Defender's

    "Security at a Glance" screen, by clicking on Defender's Icon on the Taskbar.

    The screen should contain 7 options. 5 of which should be checked green. For any that

    are checked otherwise, try to satisfy the message that they present.

    If you only see 6 options, or the screen is blank, please respond with that info.

    In case that the services that are essential for Defender to function, were corrupted

    in the removal of Santivirus, check in the "Services App" to ensure that these three Services

    have the correct status.

    1. Security Center  Should be running and set for Automatic (Delayed) start.

    1. Microsoft Defender Antivirus Service  Running and set for Automatic start.
    2. Windows Security Service  Running and set for Manual start.

    Please reply if any are not correct.

    Glen

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  5. Anonymous
    2020-12-18T00:39:13+00:00

    Hi Glen, I went into safemode, downloaded malwarebytes, ran the program, it found 33 threats, quarantined them and restarted. Now when I go to windows defender it says "Malware bytes turned on" and there is no option for windows defender to do a scan. I looked in the file location and the file SAntivirusEngine.dll is still there, but thhe malware bytes software did find a bunch of things that it fixed related to SAntivirus it seems. I ran another scan not in safe mode and the computer came back clean. I saw another commenter said malware bytes fixed their problem but after the free trial the issue came back.

    How will I know the issue is resolved/ will I need malware bytes permanently to solve the issue?

    Thanks!

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments