Windows Defender Identifies The SAME PUP As A Threat Repeatedly

Anonymous
2020-06-16T21:00:07+00:00

Since the implementation of W10 V2004, Windows Defender has now been defaulted to identify

PUPS as a threat.  As a result, many are now made aware of their presence.  And they are "remediated",

on the spot, to prevent them from causing any mischief.

The problem occurs on the subsequent scans with Windows Defender. It identifies the same PUP again,

and again. It has been determined that this is caused by the presence of the PUP in Protection History.

It appears that the default remediation that Windows Defender applies to PUPs is to Block them,

then leave them in Protection History .

EDIT:  It has been found that malware other than PUPS, can require this same procedure.

           Some have discovered, that even Trojans exhibit this same characteristic, when remediated by

          Windows Defender in W10 v2004.

If you have any malware, remediated by Windows Defender, that alerts repeatedly, this procedure applies to

it as well. In order to cleanup the malware completely, find the file in the "container file" in the Protection

History record, and delete the file that is described. If you can't find or access the file, run the Microsoft

Safety Scanner. It uses the same definitions as Windows Defender, and should remediate  the file.

https://docs.microsoft.com/en-us/windows/security/threat-protection/intelligence/safety-scanner-download 

Then proceed to delete the Protection History info.

END EDIT.

Windows Defender is defaulted to scan its own "Scans/History". Resulting in the discovery of the malware over

and over again.  Even though, other scanners see no evidence of the malware on the PC.       It doesn't exist!

Until Microsoft sees fit to fix this problem,  you can prevent the repeating error indication, by deleting the

items that are described in Windows Defender Protection History. You can delete them by accessing their files,

that are located in C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service.

In the "Service" folder, find and delete "Detection History"

Note:  ProgramData is a hidden file. In order to access it, the "Hidden Items" option in "File Explorer" must be

checked.  Find the "Hidden Items" check box under the "View Tab".

And, the first time that you access "Scans", you must select "continue", to obtain the permission.

Restart and try another scan.    Notifications for the current malware should stop.  

However, this program miscue will probably reoccur, when the next PUP / Malware is encountered.  

Glen

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

188 answers

Sort by: Most helpful
  1. Rob Koch 26,160 Reputation points Volunteer Moderator
    2021-07-10T05:38:01+00:00

    Glen,

    Seeing this discussion brings to mind a thought I had recently regarding this long-running apparent issue with Defender false detections, which I'd also initially tended to blame on Microsoft.

    However, the length of time involved along with the apparent inconsistency as to which specific malware detections trigger it are what brought another possibility to mind.

    That thought was that though I'd seen this issue myself shortly after it was first noticed and this thread created, I've not seen it again, so the combination of transient issues required to cause it must be relatively unique. That led to a belief that this isn't a simple flaw in the Microsoft scanner, but more likely the more typical combination failure where 2 or more applications, most often security apps, are interacting to cause the failures.

    The immediate question then became, what other application might be involved, since I haven't personally installed an active 3rd-party AV app since roughly 2005 when the first beta versions of the Microsoft scanners became available.

    Or so I thought anyway, since it then occurred to me that I'd unintentionally been doing just that a few times a year, though for various reasons I'd never considered this a potential issue.

    The potential offending 3rd-party app? Malwarebytes Anti-Malware, one of the very sanity check tools we recommend in order to confirm that these or other spurious detections aren't truly malware.

    The issue here is that in more recent releases, the "free" version of Malwarebytes AM is exactly the same as the trial of the Premium version, which now automatically enables itself for the 14-day trial period unless you specifically turn it off.

    So what if the minimal AV portions of Malwarebytes, along with other overlapping protections for items such as PUPs, which Microsoft themselves only more recently enabled for automated detection, might somehow be interacting during these short trial periods?

    Now we have a possible explanation for apparently random, but relatively regular events that also seem to come in batches, similar to the update cycles for a security app release. In fact, I personally just received one of these updates on the only Windows 10 system where I have Malwarebytes installed, while I can say with certainty I've never seen this spurious detection issue on any other Windows 10 or 8.1 system I own.

    Unless I'm deluding myself I think I may have found the elusive combination of apps and mostly transient update and trial period situations, which must necessarily coincide with at least one current (or possibly recent) Defender detection incident in order to trigger the initial false positive.

    Which app is specifically at fault isn't truly important, since in all such cases it's always both, as the conflict they're creating is something that neither developer has anticipated within their own app, while the particular combination of events should never occur.

    So asking whether those affected by future incidents had either Malwarebytes Anti-Malware trial or possibly another 3rd-party security app active in parallel with Defender's real-time protection when the initial looping false positive issue began, might be something that should be asked in future threads.

    Rob

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  2. Anonymous
    2021-05-16T18:08:44+00:00

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  3. Anonymous
    2021-01-08T22:27:27+00:00

    Hi Djvesic,

    You are not the first to run into this situation. It can be caused by the presence of certain

    malware on your PC. 

    Download and run a full scan with MalwareBytes. Set it to Scan for Rootkits, and allow it

    to cleanup all that it finds.

    You can find a free copy of MalwareBytes at MalwareBytes.com.

    Then follow the instructions that follow. This helped a fellow poster, with your situation.

    Hi Labeeb,

    Your inability to access "Scans", even in administrative mode, is disconcerting.

    That may indicate the presence of corruption in your OS.

    You can test for that condition by using DISM and SFC. If you like, enter Command Prompt

    by clicking "Start" and type "cmd". Select "Run as Administrator".  On the Command Prompt

    Admin screen, type the following commands.

    DISM /Online /Cleanup-Image /RestoreHealth  and hit <enter>.

    Allow it time to finish. It takes a little while. 

    Then type SFC /scannow   and hit <enter>  Allow it time to finish.  If it finds any errors,

    run it again, until it runs clean.

    Type Exit to leave Command Prompt.

    Restart your PC, and see if you can access "Scans" now.

    If you can't, it may be necessary to perform a Repair Upgrade. The procedure replaces

    your OS, but keeps your Apps & Files. If you have been able to overcome the repeating

    alert from Defender, using the methods previously described, you may not want to go

    this far.        However,  

    The Repair Upgrade is a very solid procedure, if your PC configuration is HDD only or

    SSD only. The two combined, has been problematic a few times in the past. If that is

    your PC configuration, you should create a system backup, before proceeding.

    Should you elect to do the Repair, you download the Creation Tool from here.

    https://www.microsoft.com/en-us/software-download/windows10

    Right click the downloaded file and choose "Run as Administrator".

    Choose "Upgrade this PC now" and the procedure will begin. Answer any questions

    logically, and when asked "what to keep", ensure that both the OS and Apps & Files

    are selected.

    The procedure takes about an hour to complete. Your PC will restart several times. And

    sometimes it appears to be doing nothing. Be patient, when it is finished your "sign in"

    screen will appear.  Your PC will be just as it was before the Repair, but without corruption.

    You should be able to access "Scans", if you ever need to again. And anything else that

    the corruption was going to affect, should not occur. 

    Good luck,  Glen

    Labeeb Khan

    Sir, I did what all you said- Opened Command prompt and did all which you said and it really worked it said that it found some threats and repaired them(I haven't given a try to open "Scans" till this time) but I also thought at that time that; actually I had a game in my pc with the extension .exe so I was just giving a deep thought about my pc issues and suddenly then it clicked my mind that I don't think so that .exe file is good for pc and I Googled it, hopefully found it so I at the very moment deleted that game and then came back and tried to open "Scans" and I was able to to the same and a popup showed to "Continue" or "Cancel". Honestly Sir, I was totally stunned at that very moment, I was so happy.

    That moment was unexplainable. Furthermore, I did what all You said and finally deleted the "Detection History" folder then restarted my pc and tbh I was very hopeful and scared at that moment. The error was no longer there and I was so happy.

    Actually all this time I was so panicked just because this is my first personal pc and it's expensive and it's been just, I think 4-5 months since I bought it so I don't want a threat so early in my pc.

    Thank you very much, Mr. Glen!!

    I am really very grateful to you.

    Good luck Djvesic,  Glen

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  4. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  5. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more