Windows 10: Malware removes Windows Defender

Discus and support Malware removes Windows Defender in AntiVirus, Firewalls and System Security to solve the problem; Hi! About two weeks ago I've got a virus, which not only wasn't found or blocked by Windows Defender but it has completely deleted Defender from... Discussion in 'AntiVirus, Firewalls and System Security' started by Gacorek11, May 14, 2020.

  1. Gacorek11 Win User

    Malware removes Windows Defender


    Hi! About two weeks ago I've got a virus, which not only wasn't found or blocked by Windows Defender but it has completely deleted Defender from system! I've used Malwarebytes to delete malware and then I used system restore to have Defender back. But two days ago the same thing happen! There is no Defender in system tray, nor working in the background. Manually launching an app shows an empty window with "At glance" text like on a screenshot below: Malware removes Windows Defender 72522788-8f1a-4f3e-ab7a-786619b795a5?upload=true.png

    There is also no WinDefend or SecurityHealthService in Windows Registry.
    Windows Update is also broken - gives an 0x80070424 error.

    Here is a report from my Malwarebytes scan:

    Registry key: 3

    Trojan.Agent, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Microsoft\Windows\Application Experience\STARTUPCHECKLIBRARY, Dodano do kwarantanny, 490, 735770, , , ,

    Trojan.Agent, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{B07CFF68-8ED4-4020-998B-0DAD7FDF806D}, Dodano do kwarantanny, 490, 735770, , , ,

    Trojan.Agent, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\LOGON\{B07CFF68-8ED4-4020-998B-0DAD7FDF806D}, Dodano do kwarantanny, 490, 735770, , , ,



    Registry Value: 2

    Trojan.Agent, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{B07CFF68-8ED4-4020-998B-0DAD7FDF806D}PATH, Dodano do kwarantanny, 490, 782993, 1.0.23708, , ame,

    RiskWare.BitCoinMiner, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNWINLOGUI, Dodano do kwarantanny, 854, 604807, 1.0.23708, , ame,



    Registry Data: 3

    PUM.Optional.DisabledSecurityCenter, HKLM\SOFTWARE\MICROSOFT\SECURITY CENTERANTIVIRUSDISABLENOTIFY, Zastąpiono, 13646, 293294, 1.0.23708, , ame,

    PUM.Optional.DisabledSecurityCenter, HKLM\SOFTWARE\MICROSOFT\SECURITY CENTERFIREWALLDISABLENOTIFY, Zastąpiono, 13646, 293295, 1.0.23708, , ame,

    PUM.Optional.DisabledSecurityCenter, HKLM\SOFTWARE\MICROSOFT\SECURITY CENTERUPDATESDISABLENOTIFY, Zastąpiono, 13646, 293296, 1.0.23708, , ame,



    Folder: 3

    PUP.Optional.Delta, C:\USERS\GACOR\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Sync Data\LevelDB, Dodano do kwarantanny, 325, 455070, , , ,

    PUP.Optional.Delta, C:\USERS\GACOR\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Sync Data\LevelDB, Dodano do kwarantanny, 325, 455070, , , ,

    PUP.Optional.Delta, C:\USERS\GACOR\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Sync Data\LevelDB, Dodano do kwarantanny, 325, 455070, , , ,



    File: 16

    Trojan.Agent, C:\WINDOWS\SYSTEM32\TASKS\MICROSOFT\WINDOWS\APPLICATION EXPERIENCE\STARTUPCHECKLIBRARY, Dodano do kwarantanny, 490, 735770, 1.0.23708, , ame,

    RiskWare.BitCoinMiner, C:\WINDOWS\SYSTEM32\WINLOGUI.EXE, Dodano do kwarantanny, 854, 604807, , , ,

    Trojan.FakeMS.TskLnk, C:\WINDOWS\SYSTEM32\STARTUPCHECKLIBRARY.DLL, Dodano do kwarantanny, 4082, 676770, 1.0.23708, 5A74DC805B2D0D63F8E75887, dds, 00716168

    PUP.Optional.Delta, C:\Users\gacor\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\000005.ldb, Dodano do kwarantanny, 325, 455070, , , ,

    PUP.Optional.Delta, C:\Users\gacor\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\000102.ldb, Dodano do kwarantanny, 325, 455070, , , ,

    PUP.Optional.Delta, C:\Users\gacor\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\000104.ldb, Dodano do kwarantanny, 325, 455070, , , ,

    PUP.Optional.Delta, C:\Users\gacor\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\000105.log, Dodano do kwarantanny, 325, 455070, , , ,

    PUP.Optional.Delta, C:\Users\gacor\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\000106.ldb, Dodano do kwarantanny, 325, 455070, , , ,

    PUP.Optional.Delta, C:\Users\gacor\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\CURRENT, Dodano do kwarantanny, 325, 455070, , , ,

    PUP.Optional.Delta, C:\Users\gacor\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOCK, Dodano do kwarantanny, 325, 455070, , , ,

    PUP.Optional.Delta, C:\Users\gacor\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG, Dodano do kwarantanny, 325, 455070, , , ,

    PUP.Optional.Delta, C:\Users\gacor\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old, Dodano do kwarantanny, 325, 455070, , , ,

    PUP.Optional.Delta, C:\Users\gacor\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\MANIFEST-000001, Dodano do kwarantanny, 325, 455070, , , ,

    PUP.Optional.Delta, C:\USERS\GACOR\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Web Data, Zastąpiono, 325, 455070, 1.0.23708, , ame,

    PUP.Optional.Delta, C:\USERS\GACOR\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Web Data, Zastąpiono, 325, 455070, 1.0.23708, , ame,

    PUP.Optional.Delta, C:\USERS\GACOR\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Web Data, Zastąpiono, 325, 455070, 1.0.23708, , ame,


    "zastąpiono" = replaced; "Dodano do kwarantanny" = Added to quarantine
    All quarantined items were deleted later.

    Windows 10 Home 64-bit
    Version: 1909
    Compilation: 18363.815

    I know that I have to reinstall system now, but first of all, Defender does not fulfill it's task, and second - I don't know where the virus comes from and how to become immune for it.

    I'm sorry for my bad english. I hope you can help me!

    :)
     
    Gacorek11, May 14, 2020
    #1
  2. Amadeus51 Win User

    Malware removal


    Understood, OldMike. I will keep your suggestion in mind. I always appreciate suggestions from those who know more than I do. I think the Malware did do more than one scan, because I had to approve removal of what it found twice. I don't see Windows Defender on the list of programs. I think it was on there before they redid the software. Pluto TV also disappeared.
     
    Amadeus51, May 14, 2020
    #2
  3. Le Boule Win User
    Get message Defender is removing Malware.

    Sounds like the malware detections may be in a browser.

    Can you give us the complete name/file path of the malware (as it appears under quarantine or on the list of detected items)?

    Have you emptied temporary internet files and rebooted the computer? Then do a manual update of WD followed by a Quick Scan.

    Any new browser extensions that need to be disabled?

    Try this free scanner:
    http://blog.emsisoft.com/2015/06/09/how-to-find-and-clean-malware-infections-with-emsisoft-emergency-kit/


    If the detections continue see the following free removal guide from Malwaretips.com:
    Remove Viruses, Trojans & Malware from Windows PC (Free Guide)

    To remove malware from Windows, follow these steps:

    STEP 1: Scan your computer with Kasperskty TDSSkiller

    STEP 2: Scan your computer with Malwarebytes Anti-Malware

    STEP 3: Stop the malicious process with Rkill

    STEP 4: Double-check for malware with HitmanPro

    STEP 5: Scan your computer with AdwCleaner

    (OPTIONAL) STEP 6: Scan your computer with Zemana AntiMalware

    (OPTIONAL) STEP 7: Reset your browser to default settings

    Regards…

    Top 10 Ways PUPs Sneak Onto Your Computer. And How To Avoid Them. | Emsisoft | Security Blog
     
    Le Boule, May 14, 2020
    #3
  4. Jaune Bel Win User

    Malware removes Windows Defender

    Windows Defender was permanently disabled by a malware

    Hi Robbie,

    You would have to remove the malware first before you can turn on the Windows Defender again. You can use the

    Malicious Software Removal Tool
    to eliminate the malware that entered your PC. Once you have removed it, you can turn Windows Defender on. You can refer to the below steps to turn on the Windows Defender:

    • Select the Start button.
    • Click Settings, then select Update & Security.
    • Click Turn on Windows Defender.

    To know more on how to protect your PC with Windows Defender, refer to this
    link
    .

    Let us know how it goes.
     
    Jaune Bel, May 14, 2020
    #4
Thema:

Malware removes Windows Defender

Loading...
  1. Malware removes Windows Defender - Similar Threads - Malware removes Defender

  2. Windows Defender reports malware, but cannot remove it.

    in Windows 10 Gaming
    Windows Defender reports malware, but cannot remove it.: Windows Defender reports malware, but cannot remove it. Event Viewer shows attempts, Defender "start actions" does not remove malware and a scan reveals the same threats. Event Viewer says Defender had a critical issue, throws 0x80508032.Have run FRST and have the two...
  3. Windows Defender reports malware, but cannot remove it.

    in AntiVirus, Firewalls and System Security
    Windows Defender reports malware, but cannot remove it.: Windows Defender reports malware, but cannot remove it. Event Viewer shows attempts, Defender "start actions" does not remove malware and a scan reveals the same threats. Event Viewer says Defender had a critical issue, throws 0x80508032.Have run FRST and have the two...
  4. Windows Defender won't remove certain malware

    in Windows 10 Gaming
    Windows Defender won't remove certain malware: Windows Defender detects multiple "PUABundler:Win32/PhotoScapeBundler," When I select Remove or Quarantine and click Start actions, nothing happens. The malware stays there for weeks. Although the threat is low, it's not present to have them. Two other antivirus software...
  5. Windows Defender won't remove certain malware

    in Windows 10 Software and Apps
    Windows Defender won't remove certain malware: Windows Defender detects multiple "PUABundler:Win32/PhotoScapeBundler," When I select Remove or Quarantine and click Start actions, nothing happens. The malware stays there for weeks. Although the threat is low, it's not present to have them. Two other antivirus software...
  6. Windows Defender won't remove certain malware

    in AntiVirus, Firewalls and System Security
    Windows Defender won't remove certain malware: Windows Defender detects multiple "PUABundler:Win32/PhotoScapeBundler," When I select Remove or Quarantine and click Start actions, nothing happens. The malware stays there for weeks. Although the threat is low, it's not present to have them. Two other antivirus software...
  7. Windows Defender does not remove malwares

    in AntiVirus, Firewalls and System Security
    Windows Defender does not remove malwares: Hello, I am using Windows 8.1. Every time I scan my laptop, Windows Defender detects these malwares : Trojan:Win32/Occamy.C48 VirTool:Win32/Obfuscator.C Trojan:Win32/Malex.gen!E Trojan:Win32/BlueTeal!rfn All of them show as severe active threats. When I...
  8. Problem Removing Malware in Windows Defender

    in AntiVirus, Firewalls and System Security
    Problem Removing Malware in Windows Defender: Recently, I scanned my USB and it found a malicious file. I reformat my USB But according to my Windows Defender its still there, And i tried to remove but it's still coming back, so i scanned my PC it said there were no threats. How can I remove this? because still it...
  9. Windows Defender only partially removing malware

    in AntiVirus, Firewalls and System Security
    Windows Defender only partially removing malware: Hi I have a Windows 10, 64bit platform. I noticed that my screen was momentarily going black when opening some applications mainly Microsoft ones. One suggestion was to download the virus checker from Microsoft MSERT which I did and ran. It picked up the...
  10. Malware disabled (or removed) Windows Defender

    in Windows 10 Ask Insider
    Malware disabled (or removed) Windows Defender: Here's what happened: i started my laptop normally and i went AFK for a while, the fan went full power, it was weird because I've never heard it going so fast, so I opened task manager to search for the culprit and the fan went slow again, I IMMEDIATELY thought "cryptominer",...