Defender Error: Failed, 0x80508026. Cannot remove...

G

Guest

Defender detected a backdoor but when Remove is requested it gives that error
and even throws an error dialog: "Windows Defender encountered an error:
0x80501001. One or more actions could not be completed successfully."

Its actually a dll file inside a zip (not-passwordprotected etc, standard
file.)

Any ideas?

- Matt
 
B

Bill Sanderson

Both of you have malware in place (presumably--could be a false positive,
but..)--so you qualify for PSS's free help with virus or security patch
issues.

In the United States or Canada, call 1-866-pcsafety.

Elsewhere call the local Microsoft subsidiary or number for paid support in
your area.

--
 
M

Mike Treit [Msft]

This error will occur if a threat is detected inside of a container such as
a ZIP file, RAR archive, etc.

The "remove" action cannot (in most cases) be applied to an object inside of
such containers, without deleting the entire container.

It might be worth noting that the original Antispyware beta did not have the
ability to scan inside such containers.

We still need to work on the best way to handle this scenario. The issue is
that you may have a ZIP file with tons of non-malicious file in it, but one
or more "bad" files as well that are detected. The question is: how should
we handle that? Deleting the entire container may inadvertently delete the
clean files as well, and that might not be what you want.

For now you can check if the ZIP file has anything else inside of it that
you want to keep. If not, just delete the ZIP file yourself and you will
have removed the threat.

If you really want to keep the ZIP file around but do not want to see this
error (and again, you can expect that in the future we will have a better
story here - at least not such a cryptic error message) you can disable
scanning inside archives. Clear the checkbox for "Scan inside archives" in
the General Settings section under the Tools menu. Generally, threats inside
archives, while good to know about, are not "active", meaning they can't do
anything bad to your system while inside the archive.

Thanks

-Mike
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top