VOGONS

Common searches


First post, by eddman

User metadata
Rank Member
Rank
Member

This is a bit of an odd one. I'll try my best to explain it properly.

I mounted a CD image from an old PC magazine and it just happened to have an infected file on it. Defender flagged the file, threw up an alert, and presented the typical quarantine, clean, remove and allow options.
The first three don't work because a file on a CD (or image) cannot be modified, so as soon as I select any of them, the alert comes back up again. It also throws a taskbar pop-up, and the defender icon now has a red cross.

The only "solution" is to allow that type of malware, but I don't want to have such a thing whitelisted. I don't intend to use that image anymore, so I don't even need that stupid file to be allowed.

Microsoft in its massive wisdom did not include a simple "dismiss alert" option just for such occasions.

Now my question is, is there a way to delete defender alerts, perhaps by deleting system files somewhere, or maybe to reset defender completely to its original state?

I found a guide online for deleting the protection history, but that has no effect on alerts.

EDIT:

Found a solution:

Navigate to "C:\ProgramData\Microsoft\Windows Defender\Scans\history\Service" and delete everything inside.

If windows doesn't allow it, boot into the Recovery Environment and delete it there.

Last edited by eddman on 2024-02-21, 09:03. Edited 1 time in total.

Reply 4 of 5, by Masaw

User metadata
Rank Newbie
Rank
Newbie

what was the name of the malware detected? windows defender is notorious in flagging old programs especially those packed or encrypted ones as "infected" by a virus, or such programs can be one of those called "Potentially Unwanted Applications" (PUA)

VCheck+ Portable Antivirus for DOS
=========================
https://archive.org/details/VCHECK/

Reply 5 of 5, by Errius

User metadata
Rank l33t
Rank
l33t

A problem I had last year was PDF files with embedded links that now point to malware sites. Defender was massacring my ebook collection, just deleting the files without giving the option to ignore/override the action. I had to put the entire ebook directory in the Exclusions directory, then restore the deleted files from backup.

I just tested this again now, and it no longer seems to mind these files. I guess a lot of people complained.

Is this too much voodoo?