Share via

How do I delete items quarantined by Windows Defender?

Anonymous
2024-09-29T05:48:01+00:00

"C:\ProgramData\Microsoft\Windows Defender\Quarantine"

The above folder is inaccessible.

I've run MpCmdRun.exe -Restore -ListAll and there are item in there.

How do you delete these?

Thanks

Windows for home | Windows 11 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

3 answers

Sort by: Most helpful
  1. Sumit D - IA 166.8K Reputation points Independent Advisor
    2024-09-29T11:02:38+00:00

    Thank you.

    >>1. Is this stuff kept, or is it just a reference?

    If you have cleared items, it must be a reference.

    >>2. If the latter, where is this reference kept?

    Possibly in some database or Registry - I will need to check those resources.

    >>3. The Windows Defender folder shows 615Mb - surely this isn't just the program, it's storing something.

    Same. I think that is the Windows Defender Data.

    Hope that helps, and rely on us for any further inquiries. All the best.

    1 person found this answer helpful.
    0 comments No comments
  2. Anonymous
    2024-09-29T08:29:52+00:00

    Ok thanks for that.

    So, if you run in a command propmpt:

    C:\Program Files\Windows Defender>MpCmdRun.exe -Restore -ListAll

    It states:

    The following items are quarantined:

    ThreatName = Trojan:Script/Wacatac.B!ml

    AND it lists, for me , around15 thread names... one after the other.

    So I suppose the questions are:

    1. Is this stuff kept or is just a reference?
    2. If the latter, where is this reference kept?
    3. The Windows Defender folder shows 615Mb - surely this isn't just the program, it's storing something.

    Cheers.

    0 comments No comments
  3. Sumit D - IA 166.8K Reputation points Independent Advisor
    2024-09-29T06:28:22+00:00

    Hi DiggerDavey,

    I'm Sumit, here to answer your query at the Microsoft Community.

    Apologies for any inconvenience you are experiencing. We are happy to help you.

    Yes. You can't access that folder. This is by design. You won't want certainly that the virus should spread, hence the folder is protected.

    Do these steps not help remove quarantined items?

    Press the Windows key and type Windows Security.

    Click on the Windows Security app from the search results.

    In the Windows Security window, click on Virus & threat protection.

    Under the Current Threats section, click on Protection History.

    In the Protection history window, use the Filters drop-down menu to select Quarantined items.

    Click on the quarantined item you want to remove.

    A window will pop up; click Yes to confirm.

    Click on the Action button and select Remove.

    You can also use Remove-MpThreat CMDLET to remove the quarantined threats in Powershell.

    Hope that helps, and rely on us for any further inquiries. All the best.

    0 comments No comments