Windows 10: Win10 2004 defender identifies virus threat even though file had been deleted

Discus and support Win10 2004 defender identifies virus threat even though file had been deleted in AntiVirus, Firewalls and System Security to solve the problem; Hello, Some weird stuff with MS Security Virus & threat protection since upgrading to Win10 2004. It's identifying a current threat... Discussion in 'AntiVirus, Firewalls and System Security' started by J-G-Hall, Jul 13, 2020.

  1. J-G-Hall Win User

    Win10 2004 defender identifies virus threat even though file had been deleted


    Hello,


    Some weird stuff with MS Security Virus & threat protection since upgrading to Win10 2004. It's identifying a current threat PUA:Win32/InstallCore that I cannot remove even though the file associated with the threat was previously deleted. The threat was first identified back on 7/3/2020 and that's when I manually deleted the file. Since then I've tried to remove the threat associated with a non-existent file in Virus & threat protection, but every time I rescan after removing, it reappears. Also, the Quick Scan is taking 10 to 15 minutes to complete. It gets to about 85% complete then seems to stop for awhile, before it finally completes showing the threat.


    Any suggestions for what I can try? Is there any way of resetting Defender to flush its record of threats and start over? I have tried installing Win10 2004 on top of Win10 2004 retaining data and apps, but that makes no difference. I'd prefer not to do a full OS reinstall unless I absolutely have to.


    Also, I temporarily installed Malwarebytes and ran a full scan -- it found no threats. It seems that Defender is stuck thinking there is still a threat.


    Thanks in advance.

    :)
     
    J-G-Hall, Jul 13, 2020
    #1
  2. Try3 Win User

    Windows defender false positive - forced to allow threat

    Windows defender has started to identify C:\Windows\System32\mshta.exe as a threat [normally reported as a Trojan Powessere.G]. I use mshta.exe to run an hta custom MsgBox - I have been hoping to keep using my current CustomMsgBox tool [batch file calling a vbs-hta file] until later this year when I hope to have had enough time to replace it with a PowerShell alternative.

    Windows defender's notification lets me "allow the threat" but that seems to me to be a bigger security hole than is necessary - it will now ignore a potentially real intrusion when all I want to run is a genuine Windows component. My immediate problem is fixed but I would prefer to fix the false positive using the exclusions list.

    I cleared the 'Allowed threats history' so I could use the exclusions list instead. I added C:\Windows\System32\mshta.exe to the file exclusions list and I checked that it had taken properly by checking the exclusions list both in the UI & in the Registry. But the exclusion made no difference, it continued to detect and block the exe.

    I have repeated the attempt several times [by clearing the allowed threats list & exclusions list beforehand] and the results are the same every time
    - allowing the threat works,
    - using the exclusions list has no effect.

    I studied the relevant tutorial but have not spotted an error in what I have been doing - Add or Remove Windows Defender Exclusions

    Does anybody with experience of using the exclusions list to counter false positives have any suggestions for me?

    Denis
     
  3. Cannot turn on Windows Defender virus protection

    I had the same sort of symptoms. In the Windows Security Center, under Virus and threat protection, it said "Your virus & threat protection is managed by your organization."


    Win10 2004 defender identifies virus threat even though file had been deleted wm5Jc.png


    I note you mentioned the Registry Keys under HKLM/SOFTWARE/Microsoft/Windows Defender. Nice spotting, but it seems like there is another key that is causing the problem for some users.

    Steps to a solution:

    1. Press the Windows key and type "regedit"
    2. On the regedit icon that appears, right-click and select Run as Administrator.
    3. Navigate to the folder located at HKLM\SOFTWARE\Policies\Microsoft\Windows Defender (You can paste this into the address box at the top of the window, or navigate manually using the side directory structure)
    4. In this folder, there are probably two keys. Right-click and Delete the DisableAntiSpyware key.
    5. Exit regedit, and return to the Windows Defender settings screen (refresh it if necessary). Windows Defender should have the scan options available and working.

    Solution adapted from here, with a much more detailed solution here.
     
    MechtEngineer, Jul 13, 2020
    #3
  4. JCH54 Win User

    Win10 2004 defender identifies virus threat even though file had been deleted

    virus and threat protection

    Virus and threat protection has stopped and will not restart, Windows 10 ver 1709, antimalware client ver 4.12.16299.15 . SuperAntiSpyware installed.

    I have tried most of the suggestions from the support pages, all have been ineffective. Any suggestions

    Moved from: Virus and Malware / Windows Defender / Updating Virus and Spyware Definitions / Windows 10
     
    JCH54, Jul 13, 2020
    #4
Thema:

Win10 2004 defender identifies virus threat even though file had been deleted

Loading...
  1. Win10 2004 defender identifies virus threat even though file had been deleted - Similar Threads - Win10 2004 defender

  2. microsoft defender virus and threat protection

    in AntiVirus, Firewalls and System Security
    microsoft defender virus and threat protection: Virus and threat protection in Settings, Security at a glance "Threat service has stopped. Restart it now." "Unexpected error. Sorry, we ran into a problem. Please try again."Account protection, Firewall & Network protection, App & browser control, and Device security are all...
  3. virus & threat protection settings in defender

    in AntiVirus, Firewalls and System Security
    virus & threat protection settings in defender: I have Personal Surface pro device ,,,, why in Virus and threat protection settings --- Cloud delivered protection and automatic sample submission can't be turned on????? I just have MS defender no other antivirus or spyware programs on my device. It syas settings managed by...
  4. Shows me a threat under 'Virus and Threat Protection' even though there is nothing there in...

    in AntiVirus, Firewalls and System Security
    Shows me a threat under 'Virus and Threat Protection' even though there is nothing there in...: Hey, I have a question. Recently I saw that I had a threat and that it was red urgent so I decided to see what it was. When I saw it, it said that there are threats and I should start actions with the recommended settings. Now, there were 3 issues: 1 Whenever I tried to click...
  5. WIN10-2004 Security Can't Delete Virus

    in AntiVirus, Firewalls and System Security
    WIN10-2004 Security Can't Delete Virus: First, fix the Feedback Hub. I got tired of watched the six dots circle on my screen. My computer has a serious problem with how WIN10-2004 handles viruses. It complained that I had several viruses associated within the same sub-folder of the parent folder. I selected...
  6. Windows defender deletes "trojans" even though it's off.

    in Windows 10 Ask Insider
    Windows defender deletes "trojans" even though it's off.: I went into regedit and disabled windows defender but it still deletes files that I download that it deems to be malicious. I've also tried adding exclusions but that doesn't seem to do anything and my exclusions list is still empty despite me repeating the process. I'm on...
  7. Threats identified by Windows Defender not removed

    in AntiVirus, Firewalls and System Security
    Threats identified by Windows Defender not removed: Hi, my OS is Windows 10 Pro 64bit Version 2004 Build 19041.450. After performing a full scan of my SSD, Windows Defender identified a number of threats such as APP:CDisplayEx_BundleInstaller, PUA:Win32/Vtools, PUA:Win32/InstallCore, PUA:Win32/SystemChecker,...
  8. Windows Defender Anti Virus Not Deleting Detected Threats

    in AntiVirus, Firewalls and System Security
    Windows Defender Anti Virus Not Deleting Detected Threats: Hello I have This Proble last 2 days ago I Got Infected With Win32.Ramnit.C,A,J,N all Type of This C*AP When I Scanned With Quick SCan Mode It Does'not Detected Files only Detected Two or Three File But When I Launched Full SCan Mode It Detected Every Htm,Html,some games...
  9. Virus and threat protection shows threats found, but the files have been deleted

    in AntiVirus, Firewalls and System Security
    Virus and threat protection shows threats found, but the files have been deleted: My windows defender found some threats in the kali linux iso file for obvious reasons. Now I have already deleted the file before taking actions through the windows defender. But its still showing threats from that file. How to get rid of it. [ATTACH]...
  10. Windows Defender Virus and Threat Detection

    in AntiVirus, Firewalls and System Security
    Windows Defender Virus and Threat Detection: Windows Defender Virus and Threat Detection turns off and won't restart https://answers.microsoft.com/en-us/windows/forum/windows_10-security/windows-defender-virus-and-threat-detection/a5ac7da0-b8d0-4fed-9ac4-0ecc992a2059"