Windows 10: Windows Defender Stuck on Removing Severe Threat

Discus and support Windows Defender Stuck on Removing Severe Threat in AntiVirus, Firewalls and System Security to solve the problem; I scanned my PC's with this Microsoft Safety Scanner - Free Virus Scan with the Microsoft Safety Scanner The scan found a lot of malware and... Discussion in 'AntiVirus, Firewalls and System Security' started by kstavert, Aug 8, 2016.

  1. kstavert Win User

    Windows Defender Stuck on Removing Severe Threat


    I scanned my PC's with this Microsoft Safety Scanner - Free Virus Scan with the Microsoft Safety Scanner


    The scan found a lot of malware and removed all but three items - severe -
    and i read that Windows Defender would complete the job/remove the
    malware.

    the three remaining items are:
    VirTool:JS/Obfuscator.HO
    VirTool:JS/Obfuscator.HS
    VirTool:JS/Obfuscator.HN

    my question is - is WD stuck. the message reads "applying your actions
    this might take a few SECONDS.

    Well, I started it at about 7 a.m. this morning and it's been sitting at about
    2/3 the way through the process for almost that entire 13 hours.

    Do i just leave it alone? Restart it? Any suggestions?

    thanks
    Karen

    :)
     
    kstavert, Aug 8, 2016
    #1

  2. Defender's removal of severe threats

    I am sorry to say that I only a user and to be honest its very hard to make sentence for this question specially that I am new to use the computer. May be one day I am a genuse of the computer
     
    rperez5342, Aug 8, 2016
    #2
  3. Defender's removal of severe threats

    I followed these instructions, but the system would not let me paste the copied item, the command. I tried again, was able to paste the command but then got the following response:

    Copyright (C) Microsoft Corporation. All rights reserved.

    PS C:\WINDOWS\system32> Set-MpPreference -ScanPurgeItemsAfterDelay 10 DAYS.

    Set-MpPreference : A positional parameter cannot be found that accepts argument 'DAYS.'.

    At line:1 char:1

    + Set-MpPreference -ScanPurgeItemsAfterDelay 10 DAYS.

    + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    + CategoryInfo : InvalidArgument: Windows Defender Stuck on Removing Severe Threat :)) [Set-MpPreference], ParameterBindingException

    + FullyQualifiedErrorId : PositionalParameterNotFound,Set-MpPreference

    PS C:\WINDOWS\system32> Set-MpPreference -ScanPurgeItemsAfterDelay
     
    Baerbel1960, Aug 8, 2016
    #3
  4. simrick Win User

    Windows Defender Stuck on Removing Severe Threat

    Hi Karen and welcome to Tenforums.

    No, it shouldn't take that long - it's having difficulty.
    Please run RKILL. Do NOT reboot.
    Then run MBAR.
    You should now be able to run Windows Defender to get rid of those infections..
    Then run TempFile Cleaner.
    Then run JRT (Junkware Removal Tool).
    Finally, run ADWCleaner.

    That should do it. *Smile
     
    simrick, Aug 8, 2016
    #4
  5. Slartybart, Aug 8, 2016
    #5
  6. kstavert Win User
    WD was definitely having trouble... it was in the same spot
    this morning.

    Thank you soooooo very much for your help

    I actually started all of this with ADWCleaner because
    the following two registry files would not be removed.

    type
    Key HKCU\software\Microsoft\Windows\CurrentVersion\Ext\Stats\(10921475-03CE-4E04-90CE-E2E7EF20C814)


    HKCU\software\Microsoft\Windows\CurrentVersion\Ext\Settings\(10921475-03CE-4E04-90CE-E2E7EF20C814)

    I ran ADWCleaner 4 or 5 times to try to get it to delete
    these files...

    then, I ran the Microsoft tool and WD...

    Just ran all of the programs you recommended and finished
    with ADWCleaner... and guess what???

    These two registry files are still there!!!!!!!

    Any suggestions?

    I've not manually cleaned anything from the registry before

    Again, thank you very much

    Karen
     
    kstavert, Aug 8, 2016
    #6
  7. kstavert Win User
    Thank you...

    now, you say to burn a cd... will jump drive do the
    same thing?

    Karen
     
    kstavert, Aug 8, 2016
    #7
  8. Borg 386 Win User

    Windows Defender Stuck on Removing Severe Threat

    I'm seeing some references that say some of the Obfuscator variants plant a rootkit, therefore, d/l & run TDSSKiller.

    TDSSKiller Download

    I see you started with AdwCleaner, the recommended action would be to run RKill first to attempt to terminate the malicious processes. After running this, do not reboot, proceed to scanning with your malware scanners. Please take a moment to read the documentation on the d/l page.

    RKill Download

    Being that the malware scanners cannot remove the reg keys, you may have to navigate to those points in the registry & manually delete them.
     
    Borg 386, Aug 8, 2016
    #8
  9. simrick Win User
    So these 2 keys were identified by ADWCleaner as rogue and needing to be removed? Have you tried running ADWCleaner in safe mode to get rid of them?
    Borg is right, you may have to go in and delete them yourself. Just be sure to back up your registry and create a restore point first. *Wink
     
    simrick, Aug 8, 2016
    #9
  10. Sure, you can put Windows Defender Offline on a jump drive.

    But the emphasis of my post is that you no longer have to do that ...
    you can launch Defender Offline from Settings > Update and Security > Defender > Defender Offline
    as described here: Defender Offline

    simrick (safe mode Adwcleaner with a question about the reg entires) and Borg (tdssKiller, Rkill, possible manual reg entries removal) have offered other suggestions - it helps troubleshooting if you always follow the order of the suggestions and report the results.

    When you've completed all on-demand scans and other remediation steps, run the following (both commands take a while to complete).

    If there are any integrity issues reported in the results on the screen,

    Launch Command Prompt (Admin)

    Dism /Online /Cleanup-Image /RestoreHealth

    SFC /ScanNow
     
    Slartybart, Aug 8, 2016
    #10
  11. If you have any IObit software on your machine - please uninstall those
    If you paid for the software make sure you have a key to reinstall (not recommended)
     
    Slartybart, Aug 8, 2016
    #11
  12. kstavert Win User
    I followed the recommendations that I was given here...

    when I wrote, "I started with ADWClearner" - that was
    BEFORE I came here... the Reg Keys that would not
    delete are why i started looking for answers and how
    I ended up here.

    I ran everything I was advised to run - in the order as
    listed and now one of my PC's is squeaky clean...

    I can't thank you enough... another has the same
    crap on it and I'm going through the same process
    on it.

    You guys are the best. thanks

    Karen
     
    kstavert, Aug 8, 2016
    #12
  13. Windows Defender Stuck on Removing Severe Threat

    Stay safe my comrade.
     
    RubberDucky, Aug 8, 2016
    #13
  14. Borg 386 Win User
    I'm sorry if I misinterpreted that & I'm glad you got it sorted. *Biggrin

    If possible, can you post which cleaners you ran & which one deleted the infection so we'll have a reference point down the road should this happen to someone else.

    Also, once you have confirmed a clean system, take some time to make a system image. This will be invaluable down the road should your OS be compromised badly or hit with ransomware. Follow the tutorial & keep your images on a external HDD/Flash Drive that is not connected to the computer at all times. Make images on a regular basis. Keep 2 or 3 older ones just in case you inadvertently make one with malware.

    System Image - Create in Windows 10 - Windows 10 Forums

     
    Borg 386, Aug 8, 2016
    #14
  15. kstavert Win User
    Hi Slartybart

    What does iObit have to do with this?

    I have used their uninstaller..... I will
    remove it from my PC's

    Thanks
     
    kstavert, Aug 11, 2016
    #15
Thema:

Windows Defender Stuck on Removing Severe Threat

Loading...
  1. Windows Defender Stuck on Removing Severe Threat - Similar Threads - Defender Stuck Removing

  2. Windows defender threat "removed or restored" but still comes up as 1 threat found

    in AntiVirus, Firewalls and System Security
    Windows defender threat "removed or restored" but still comes up as 1 threat found: Hello, I downloaded a program and got infected with Trojan:Win32/Conteban.B!ml When Windows Defender alerted me, i deleted the folder that was downloaded and emptied my recycle bin. Since then, i have re-scanned my computer a few times and it always shows "1 threat found"...
  3. severe threat detected

    in AntiVirus, Firewalls and System Security
    severe threat detected: I'm getting a severe virus threat that continually is trying to load. Defender cleaned most of them except this one: [ATTACH]What should I do about this? https://answers.microsoft.com/en-us/windows/forum/all/severe-threat-detected/c98323e0-f01b-4a61-ba62-6a6c9aa3cf48"
  4. Windows Defender detected threat but unable to remove

    in AntiVirus, Firewalls and System Security
    Windows Defender detected threat but unable to remove: Hi community, My windows defender just found a threat in my com: Threat detected: Program:Win32/Wacapew.B!ml Alert Level: Medium Category: Potentially Unwanted Software Details: This program has potentially unwanted behavior Affected items: file:...
  5. removing threats with windows defender

    in AntiVirus, Firewalls and System Security
    removing threats with windows defender: So iv chosen what actions to perform which are to remove and made no action on the threats blocked as i dont want them to be allowed to stay. So how do i tell windows to caring out these actions? Im currently looking under Protection history...
  6. Windows Defender: no option to remove threat in Win. 10, 1903

    in AntiVirus, Firewalls and System Security
    Windows Defender: no option to remove threat in Win. 10, 1903: hi Microsoft: I downloaded something but was notified that there it was a threat. But there is no option to remove or clear the threat in the 1903 version of Windows 10. I have to manually do it. In the older versions of Windows 10, there is an option to clear threats....
  7. Windows Defender Stuck while removing "Threat"

    in AntiVirus, Firewalls and System Security
    Windows Defender Stuck while removing "Threat": It discovered a thread which isn't a real threat. Now it is stuck for an hour trying to removing it, while it is not progressing at all and at the same time it wastes 25% of my CPU constantly. I can't terminate the process either, not even as administrator. The only thing I...
  8. Windows defender won’t remove threat Trojan:Win32/Bitrep.A

    in AntiVirus, Firewalls and System Security
    Windows defender won’t remove threat Trojan:Win32/Bitrep.A: defender detects threat. Action taken to remove. Have run quick scan, full scan and advanced offline scan. Offline restarts windows but does not apear to take action as threat warn returns as soon as i go back online...
  9. Windows defender threat warning

    in AntiVirus, Firewalls and System Security
    Windows defender threat warning: I am getting a Windows Defender threat warning saying BrowserModifier:Win32/Polted. It will not remove nor quarantine. In addition the warning does not come on with every restart. At a loss as to what is the problem.
  10. severe threat is windows defender?! What?!

    in AntiVirus, Firewalls and System Security
    severe threat is windows defender?! What?!: I dont get it is this false positive? [img] 60008

Users found this page by searching for:

  1. windows defender cannot remove threats

    ,
  2. windows defender cannot remove severe