Share via

[Win10 Defender] Constantly detecting non-existent threat

Anonymous
2015-08-09T22:07:10+00:00

Notes: Malware bytes free detects no further threat at all, so I think it's a Defender detection error.

Kaspersky removal tool says there's nothing wrong. Microsoft Anti-malware signature tool says everything is clear.

I'll keep the question short, so any further information/log/screenshot may be asked there.

Today while cleaning my HD from old files, Windows defender found a infected file. I've immediately followed with a clean and remove action and so it did. But shortly after it kept detecting the same threat over and over, but the file isn't there anymore and even the report say something like this:

!#UACTrigger.A - Severe - 09-Aug xx:xx Clean

and under items it says:

amsiuac:DDDCBBB02F9BDE2B79DDF47309A6EA74

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

Answer accepted by question author

  1. Anonymous
    2015-08-11T00:03:52+00:00

    I've been searching the registry after that string with no luck at all. That string isn't at the registry.

    Now with the user above me stating the same with a clean install, I'm inclined to believe it's a common error/bug at the software itself. Asking around and I've found another 2 friends with the same issue. Both simply switched to a third party anti-malware solution and deactivated Defender as they understood that was a software failure. I for once wish to proceed with Defender and I humbly ask for further analysis at the development team.

    I'll proceed monitoring this post if any further info is needed.

    edit. Issue solved (apparently) -

    WARNING: This workaround may leave the machine vulnerable if the threat is real. Only do this if you've already followed every available malware removal advice there or at specialized sites and are 100% sure there's no malware on your machine.

    How: After going in circles, I've done a very simply procedure. First, I've allowedthe possible threat, forcing Defender to ignore it. That made it return to it's normal 'all clear' state (green screen and all). That done, I've proceeded to history, allowed items and removed everything from there. The loop ceased and a full scan returned that everything is ok (no threats found). Just to be sure, Malware Bytes was run at security mode and no internet connection.

    60+ people found this answer helpful.
    0 comments No comments

25 additional answers

Sort by: Most helpful
  1. Anonymous
    2016-07-01T23:11:34+00:00

    Notes: Malware bytes free detects no further threat at all, so I think it's a Defender detection error.

    Kaspersky removal tool says there's nothing wrong. Microsoft Anti-malware signature tool says everything is clear . . . But shortly after it kept detecting the same threat over and over, but the file isn't there anymore and even the report say something like this:

    !#UACTrigger.A - Severe - 09-Aug xx:xx Clean

    and under items it says:

    amsiuac:DDDCBBB02F9BDE2B79DDF47309A6EA74

    This is not a detection error. Since it says "Severe", it is likely a Trojan, and after infection, Trojans are file-less, so even if you deleted the original file, it's still in your system. Detecting the same threat over and over is likely your anti-virus software failing to delete it.

    3 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2015-10-12T10:17:03+00:00

    Hi 3ICE,

    i don't know if it will be helpful but amsiuac is actually the concatenation of two acronyms AMSI and UAC which respectively means AntiMalware Scan Interface and User Account Control (https://technet.microsoft.com/en-us/library/mt438234%28v=vs.85%29.aspx)

    By the way, I have the same error in Windows Defender since i ran keygen which was asking for admin rights

    1 person found this answer helpful.
    0 comments No comments
  3. Anonymous
    2015-08-10T00:42:10+00:00

    That's the point, there's no location at all, just that line:

    amsiuac:DDDCBBB02F9BDE2B79DDF47309A6EA74

    Even running a scan returns nothing. It just goes into a loop: A popup says a pottentialy dangerous item was found and requires my input. I say to clean it and it does all Ok. When done, about 3 seconds later it's there again. If I had the slightly clue about where it is, I would manually find/delete it myself.

    Edit, a new different line just appeared:

    !#Lua:SuspiciousPathFilename

    (amsiuac:DDDCBBB02F9BDE2B79DDF47309A6EA74)

    Edit 2, Disk cleanup didn't solved. I've downloaded and ran CCCleaner to clean any registry left-up, no luck.

    0 comments No comments
  4. Anonymous
    2015-08-10T00:31:28+00:00

    Try using Disk Cleanup.

    http://windows.microsoft.com/en-us/windows-10/disk-cleanup-in-windows-10

    In Defender History, what is the location of the threat Defender says it has detected/cleaned?

    -steve

    0 comments No comments