Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

Clearing Defender history after recent updates


  • Please log in to reply
7 replies to this topic

#1 action-undo-balance

action-undo-balance

  •  Avatar image
  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:04:46 PM

Posted 13 August 2023 - 11:47 PM

Hi,

 

Up until recently, we were able to manually clear Windows Defender's detection history. The scriptable solution was to delete C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service folder. This served as a way to ensure any history of detections in the GUI were ones I hadn't looked at yet.

 

It seems that as of the last few days, this folder is protected by Defender and can't be removed. Things I've tried:

 

- Run a command window as SYSTEM

- Ensure Tamper Protection is disabled

- Various local policies to temporarily disable Defender

- Using sysinternals MoveFile to set a delete on reboot

 

You'll still get an Access Denied attempting to tamper with these files in any way, and for some reason the GUI option to clear history was removed. Any idea how to make a history look all clear would be appreciated.



BC AdBot (Login to Remove)

 


#2 Pkshadow

Pkshadow

  •  Avatar image
  • BC Advisor
  • 12,972 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:On the Brow of the Hill, West Coast, Canada
  • Local time:10:46 PM

Posted 14 August 2023 - 01:14 AM

Hi, Should always please star your OS.

 

Going to have to try the ones you did not mention : https://www.makeuseof.com/windows-microsoft-defender-clear-history/


" mosquitoes really wake up everyday and choose violence "   — dalia (@_dalia7)
www.cnn.com/2020/07/23/health/mosquitoes-attraction-humans-future-wellness-scn/index.html
 

I-7 ASUS ROG Rampage II Extreme  / ASUS TUF Gaming F17 / I-7 4770K ASUS ROG Maximus VI Extreme


#3 action-undo-balance

action-undo-balance
  • Topic Starter

  •  Avatar image
  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:04:46 PM

Posted 14 August 2023 - 01:27 AM

Hi,

This has been experienced on both Windows 10 and 11 after last week's updates.

 

From that article: Option 1 is exactly the process described, it no longer works. Option 2 doesn't have anything to do with clearing the detection history, it works for clearing the event viewer which is unrelated. Options 3 and 4 are the same and allow you to schedule clears but don't let you clear anything manually. I'm guessing setting it to one day means you have to wait 24 hours because I've followed those processes about eight hours ago and the history hasn't cleared yet.



#4 cnfcomps

cnfcomps

  •  Avatar image
  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:05:46 AM

Posted 16 March 2024 - 11:14 AM

I may have discovered a workaround for this:

 

1. Install Malwarebytes and restart the computer.

2. Uninstall Malwarebytes but do not restart the computer immediately.

3. The Windows Security centre should show that the service is not active.

4. Delete all the files in C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service using File Explorer.

5. Restart the computer.

 

I hope this helps someone.



#5 Pkshadow

Pkshadow

  •  Avatar image
  • BC Advisor
  • 12,972 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:On the Brow of the Hill, West Coast, Canada
  • Local time:10:46 PM

Posted 18 March 2024 - 06:06 AM

@cnfcomps  The problem of doing what you say is that instead of Defender as the A/V you have switched it to MBAM as it is a full fledged A/V program as well.

 

You need to follow the instructions below to have Defender back as the A/V and make exceptions as listed so that they can run together with no problems. :

https://www.howtogeek.com/230158/how-to-run-malwarebytes-alongside-another-antivirus/

 

(as do not run Defender) Might try this as a interface to bring out the hidden controls of Defender A/V : https://www.majorgeeks.com/files/details/configuredefender.html

 

& for the Firewall use WFC by a developer now working for MBAM (review with link to Interface for Control) :

https://www.makeuseof.com/windows-firewall-control-guide/

 

Not sure how helpful these are for cleaning but............


" mosquitoes really wake up everyday and choose violence "   — dalia (@_dalia7)
www.cnn.com/2020/07/23/health/mosquitoes-attraction-humans-future-wellness-scn/index.html
 

I-7 ASUS ROG Rampage II Extreme  / ASUS TUF Gaming F17 / I-7 4770K ASUS ROG Maximus VI Extreme


#6 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 61,920 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:01:46 AM

Posted 01 April 2024 - 08:06 PM

You can also use _AW_'s (Microsoft Answers Volunteer Moderator) DWDH tool to delete detection history....download, unzip, double-click on DWDH.exe to run and restart the computer when done.


.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


#7 Pkshadow

Pkshadow

  •  Avatar image
  • BC Advisor
  • 12,972 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:On the Brow of the Hill, West Coast, Canada
  • Local time:10:46 PM

Posted 02 April 2024 - 06:14 PM

Do not know what is thought about this here @quietman7 but there is a new Windows Program : https://pcmanager.microsoft.com/en-us


" mosquitoes really wake up everyday and choose violence "   — dalia (@_dalia7)
www.cnn.com/2020/07/23/health/mosquitoes-attraction-humans-future-wellness-scn/index.html
 

I-7 ASUS ROG Rampage II Extreme  / ASUS TUF Gaming F17 / I-7 4770K ASUS ROG Maximus VI Extreme


#8 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 61,920 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:01:46 AM

Posted 02 April 2024 - 06:52 PM

PC Manager Microsoft's answer to CCleaner
 
While some features are useful, I have never been an advocate of programs which claim to boost, provide health checks and optimize Windows.
 
Microsoft’s Insane PC Manager App

I assume this is a Chinese language app that was translated into other languages, but I’m surprised that Microsoft would allow something this shoddily written to appear in public. But then I remembered the Windows Insider Blog and that we live in a new age....I strongly recommend ignoring this app.


.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users