I received warning for Win32/Defendertamperingrestore everyday

Anonymous
2021-04-13T08:00:37+00:00

I downloaded a pivot animator 3 months earlier 

It also downloaded a AVG antivirus free trial version.i deleted the antivirus and the pivot animator.it turned off my windows defender.i backed it up by seeing a youtube video but after that i am getting this win32/defendertamperingrestore everyday i scan and remove it idk how to fix it

I even tried after clearing my protection history

Pls help fast

P.S my laptops working absolutly fine

[Original Title: Malware]

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

50 answers

Sort by: Most helpful
  1. Anonymous
    2021-04-13T12:38:52+00:00

    1)reg delete "HKLM\Software\Microsoft\Windows\CurrentVersion\Policies" /f -this was partillay completed

    2)reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\real-time protection\DisableBehaviorMonitoring" /f -was "the system is unable to find the specified registry key or value"

    3)reg delete "HKLM\Software\Microsoft\WindowsSelfHost" /f -was sucesfully deleted

    4)reg delete "HKLM\Software\Policies" /f -it was partially deleted

    5)reg delete "HKLM\Software\WOW6432Node\Microsoft\Policies" /f -was sucessfully deleted

    6)reg delete "HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies" /f -was sucessfully deleted

    7)reg delete "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" /v DisableAntiSpyware -in this one it said u wanna delete it? yes/no i typed yes and it said "the system is unable to find the specified registry key or value"

    8)reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies" /f -its was deleted sucessfully

    9)reg delete "HKCU\Software\Microsoft\WindowsSelfHost" /f -it was "the system is unable to find the specified registry key or value"

    10)reg delete "HKCU\Software\Policies" /f -it was sucessfully deleted

    11)reg delete "HKLM\Software\Microsoft\Policies" /f -it was sucessfully deleted

    Thx for ur guidance but see this list and just tell is everything alright in it? or i have done anything very wrong?

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2021-04-13T12:12:18+00:00

    how can i trust you that these are the commands i need

    Was this answer helpful?

    0 comments No comments
  3. DaveM121 935.1K Reputation points Independent Advisor
    2021-04-13T09:04:59+00:00

    Hi Helpmefastt

    Yes, here is what Microsoft have to say about that win32/defendertamperingrestore on their website:

    https://www.microsoft.com/en-us/wdsi/threats/ma...

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2021-04-13T09:00:33+00:00

    are u sure?

    in how much time will it be healed?

    thx BTW

    Was this answer helpful?

    0 comments No comments
  5. DaveM121 935.1K Reputation points Independent Advisor
    2021-04-13T08:38:22+00:00

    Hi Helpmefastt

    I am Dave, an Independent Advisor, I will help you with this . . .

    You should run a scan with the free version of MalwareBytes to make sure your system is clean

    https://www.malwarebytes.com/

    Also, Microsoft indicate that Defender will recover form this problem by itself, that there is nothing further you need to do

    ________________________________________________________

    Standard Disclaimer This is a non-Microsoft website. The page appears to be providing accurate, safe information. Watch out for ads on the site that may advertise products frequently classified as a PUP (Potentially Unwanted Products). Thoroughly research any product advertised on the site before you decide to download and install it.

    Was this answer helpful?

    0 comments No comments