Windows 10: Windows Defender keeps identifying and removing this threat over and over:...

Discus and support Windows Defender keeps identifying and removing this threat over and over:... in AntiVirus, Firewalls and System Security to solve the problem; Every few minutes this gets flagged, Windows Defender quarantines it and then it comes back again. It says: AFFECTED ITEMS: file:... Discussion in 'AntiVirus, Firewalls and System Security' started by Scribe42, Feb 6, 2021.

  1. Scribe42 Win User

    Windows Defender keeps identifying and removing this threat over and over:...


    Every few minutes this gets flagged, Windows Defender quarantines it and then it comes back again.


    It says:

    AFFECTED ITEMS:

    file: C:\Users\[USERNAME]\AppData\Local\Apple Inc\CloudKit\iCloudDrive\MMCS\tmpm-0x0000000000000001


    and

    file: C:\Users\[USERNAME]\AppData\Local\Apple Inc\CloudKit\iCloudDrive\MMCS\tmpm-0x0000000000000002


    Is this a real threat? How do I get rid of it? Offline scan did not help.


    Thank you

    :)
     
    Scribe42, Feb 6, 2021
    #1
  2. Petrus07 Win User

    Threats identified by Windows Defender not removed

    Hi, my OS is Windows 10 Pro 64bit Version 2004 Build 19041.450. After performing a full scan of my SSD, Windows Defender identified a number of threats such as APP:CDisplayEx_BundleInstaller, PUA:Win32/Vtools, PUA:Win32/InstallCore, PUA:Win32/SystemChecker, PUA:Win32/PiriformBundler. I will appreciate your comments or suggestions for removal them. Many thanks.
     
    Petrus07, Feb 6, 2021
    #2
  3. Try3 Win User
    Windows defender false positive - forced to allow threat

    Windows defender has started to identify C:\Windows\System32\mshta.exe as a threat [normally reported as a Trojan Powessere.G]. I use mshta.exe to run an hta custom MsgBox - I have been hoping to keep using my current CustomMsgBox tool [batch file calling a vbs-hta file] until later this year when I hope to have had enough time to replace it with a PowerShell alternative.

    Windows defender's notification lets me "allow the threat" but that seems to me to be a bigger security hole than is necessary - it will now ignore a potentially real intrusion when all I want to run is a genuine Windows component. My immediate problem is fixed but I would prefer to fix the false positive using the exclusions list.

    I cleared the 'Allowed threats history' so I could use the exclusions list instead. I added C:\Windows\System32\mshta.exe to the file exclusions list and I checked that it had taken properly by checking the exclusions list both in the UI & in the Registry. But the exclusion made no difference, it continued to detect and block the exe.

    I have repeated the attempt several times [by clearing the allowed threats list & exclusions list beforehand] and the results are the same every time
    - allowing the threat works,
    - using the exclusions list has no effect.

    I studied the relevant tutorial but have not spotted an error in what I have been doing - Add or Remove Windows Defender Exclusions

    Does anybody with experience of using the exclusions list to counter false positives have any suggestions for me?

    Denis
     
    Try3, Feb 6, 2021
    #3
  4. Windows Defender keeps identifying and removing this threat over and over:...

    WINDOWS DEFENDER IS NOT REMOVING THREATS

    Hi lelouch.lamperouge,

    Sorry if that didn't work.

    Is the threat listed on your Quarantined Items? If yes, please try the following.

    1: Open Windows Defender Security Center from the system tray area.

    2: Click “Virus & threat protection”.

    3: Open Protection History.

    4: Click filters, select ‘Quarantined Items’

    5: Select the threat and click Remove.

    I hope this helps. Feel free to ask back any questions and keep me posted.
     
    Paul Navera, Feb 6, 2021
    #4
Thema:

Windows Defender keeps identifying and removing this threat over and over:...

Loading...
  1. Windows Defender keeps identifying and removing this threat over and over:... - Similar Threads - Defender keeps identifying

  2. Windows Defender keeps identifying and removing this threat over and over: Exploit:JS/Blacole.A

    in Windows 10 Gaming
    Windows Defender keeps identifying and removing this threat over and over: Exploit:JS/Blacole.A: Every few minutes this gets flagged, Windows Defender removes it and then it comes back again.It says:AFFECTED ITEMS:file: C:\Users\[USERNAME]\AppData\Local\Packages\AppleInc.iCloud_nzyj5cx40ttqa\LocalCache\Local\Apple...
  3. Windows Defender keeps identifying and removing this threat over and over: Exploit:JS/Blacole.A

    in Windows 10 Software and Apps
    Windows Defender keeps identifying and removing this threat over and over: Exploit:JS/Blacole.A: Every few minutes this gets flagged, Windows Defender removes it and then it comes back again.It says:AFFECTED ITEMS:file: C:\Users\[USERNAME]\AppData\Local\Packages\AppleInc.iCloud_nzyj5cx40ttqa\LocalCache\Local\Apple...
  4. Windows Defender detecting Behavior:Win32/CoinMiner.I over and over but doesn't remove it.

    in AntiVirus, Firewalls and System Security
    Windows Defender detecting Behavior:Win32/CoinMiner.I over and over but doesn't remove it.: Hi all,I've ran Defender a number of times both on and offline. Have also removed logs and excluded the Defender history folder in case it was detecting false positives from it. Still seems that I've got this issue. I've ran FRST and have the compilation logs but don't really...
  5. windows 10 keep restarting over and over

    in Windows 10 Gaming
    windows 10 keep restarting over and over: This issue happens more frequently now. I having issue using my computer since it's restarting over and over after the screen stucks. What to do? https://answers.microsoft.com/en-us/windows/forum/all/windows-10-keep-restarting-over-and-over/62787b8e-b5de-4891-a7a5-c76529df017a
  6. windows 10 keep restarting over and over

    in Windows 10 Software and Apps
    windows 10 keep restarting over and over: This issue happens more frequently now. I having issue using my computer since it's restarting over and over after the screen stucks. What to do? https://answers.microsoft.com/en-us/windows/forum/all/windows-10-keep-restarting-over-and-over/62787b8e-b5de-4891-a7a5-c76529df017a
  7. windows 10 keep restarting over and over

    in Windows 10 BSOD Crashes and Debugging
    windows 10 keep restarting over and over: This issue happens more frequently now. I having issue using my computer since it's restarting over and over after the screen stucks. What to do? https://answers.microsoft.com/en-us/windows/forum/all/windows-10-keep-restarting-over-and-over/62787b8e-b5de-4891-a7a5-c76529df017a
  8. Windows defender repeatedly shows the same threat over and over after taking action

    in AntiVirus, Firewalls and System Security
    Windows defender repeatedly shows the same threat over and over after taking action: Hello microsoft team, Recently windows defender detected Trojan:Win32/Access!rfn on my PC. After I clicked on Start Action, it is notifying the same threat everytime. I even deleted the infected file after going in the location in the threat details. But still, it shows the...
  9. Threats identified by Windows Defender not removed

    in AntiVirus, Firewalls and System Security
    Threats identified by Windows Defender not removed: Hi, my OS is Windows 10 Pro 64bit Version 2004 Build 19041.450. After performing a full scan of my SSD, Windows Defender identified a number of threats such as APP:CDisplayEx_BundleInstaller, PUA:Win32/Vtools, PUA:Win32/InstallCore, PUA:Win32/SystemChecker,...
  10. Windows Defender will not remove or quarantine a threat that is over 30 days old

    in AntiVirus, Firewalls and System Security
    Windows Defender will not remove or quarantine a threat that is over 30 days old: On 1 July 2020 Windows Defender claimed to have detected a low rated threat called PUA.Win32.DownloadSponsor but Windows Defender will not remove or quarantine it and is still detecting the threat although I am unable to find it on my computer. Windows Defender also says:...