"Windows Defender Backup" rule not working

On 05/07/2023 at 03:31, nukecad said:
<div class="ipsQuote_contents">
	<p>
		... Dave no longer works at CCleaner, there have been a few staff changes in recent months, so I doubt that anyone will see 'pings' or messages for him...
	</p>
</div>

Hi nukecad:

That for the heads up. Do you know if any of the Avast / Piriform employees are still monitoring the CCleaner Bug Reporting board and/or might respond to an @mention? I don't recall seeing seen a post in the forum by an employee for almost two months now, but I don't visit the forum on a daily basis.

-------------

Dell Inspiron 5584 * 64-bit Win 10 Pro v22H2 build 19045.3086 * Firefox v115.0.1 * Microsoft Defender v4.18.23050.5-1.1.23060.1005 * Malwarebytes Premium v4.5.32.271-1.0.2051 * Macrium Reflect Free v8.0.7279 * CCleaner Free Portable v6.13.10517

It has gone noticibly quieter as far as the Staff making posts is concerned.

There have been some indications that they are still reading posts. (well one at least when something we flagged for attention appears to have been acted on).

How often is another question.

It looks like "Windows Devender Backup" is now causing more issues if/when it is ticked for cleaning:

https://community.ccleaner.com/topic/65179-ccleaner-v61410584-crashing-on-windows-11/#comment-343691

Probably consider yourselves lucky it couldn't clean Microsoft Defender Antivirus!

Defender is easy to mess it up, and even Microsoft's own new beta cleaning tool causes nothing but grief when it cleans it (which is ticked by default to be cleaned) since Defender has to seemingly rebuild it's cache or whatever it's doing that takes way too long for it to finish rebuilding. It takes several minutes even with an SSD as the OS drive, and the rebuilding can continue upon the next reboot as if it were corrupted. In my opinion it's better left alone!

The only thing that's ever been "safe" to clean in Defender is from a now old entry from Winapp2.ini. Using it doesn't cause a very long cache rebuild or the thought that Defender has been corrupted. Instead Defender just barks softly about needing to run a system scan, and that's it, no damage done.

This is what's cleaned from that mentioned old Winapp2.ini entry:

FileKey1=%CommonAppData%\Microsoft\Windows Defender\Network Inspection System\Support|*.txt;NisLog.txt.bak


FileKey2=%CommonAppData%\Microsoft\Windows Defender\Scans\BackupStore|*.*


FileKey3=%CommonAppData%\Microsoft\Windows Defender\Scans\History\CacheManager|*.*|RECURSE


FileKey4=%CommonAppData%\Microsoft\Windows Defender\Scans\History\Service|*.log


FileKey5=%CommonAppData%\Microsoft\Windows Defender\Scans\History\Store|*.*


FileKey6=%CommonAppData%\Microsoft\Windows Defender\Scans\MetaStore|*.*|RECURSE


FileKey7=%CommonAppData%\Microsoft\Windows Defender\Scans\RtSigs\Data|*.*|RECURSE


FileKey8=%CommonAppData%\Microsoft\Windows Defender\Support|*.*|RECURSE

Once a week or so, I use the built-in Disk Cleanup utility to supplement the work CCleaner does for me. It's particularly valuable for Windows Update leftovers. But it also offers to clean up "Non-critical files used by Microsoft Windows Defender." I generally find somewhere around 20MB listed in Disk Cleanup's selection window, and if I tick that option and run Disk Cleanup's Delete Files function, and then re-open Disk Cleaner to see what it now shows for delete-able Defender files, it shows about 19Mb or more still there.

However, If I run Disk Cleanup and it finds 20MB for Defender, and I tick that choice and hit OK, and it shows the confirmation window with an option button to Delete the selected files, this works a lot better:

Leave that confirmation window open (IOW, don't hit the OK button), then open Defender's control window, and turn off Tamper Protection, and then turn off Defender temporarily (it's always temporary, because Windows will tun it back on in a few minutes at most) and THEN hit the OK button in the Disk Cleanup confirmation window, wait for Disk Cleanup to finish, and then turn Defender back on and turn Tamper Protection back on, and then open Disk Cleanup again, it will show only a few KB of Defender files.

That sounds like a lot of work, but it's not, and once you do it, it'll be easy the next time.

I'm quite sure that Disk Cleanup doesn't EVER do anything harmful to your computer. ?‍♂️?

Let's be clear: I'm not recommending that you clean up Defender's "Non-critical files," that's your business. Just saying that this is one way to do it if you choose to do it.

On 15/06/2023 at 08:29, mogli said:
<div class="ipsQuote_contents">
	<p>
		The new "Windows Defender Backup" rule doesn't delete anything here (Windows 11), any ideas?


		(That's kind of expected as the folder should have a strong anti-tampering protection.)
	</p>
</div>

Hi mogli:

I just updated to CCleaner Free Portable v6.15.10623 today and noticed that Custom Clean no longer has a checkbox for Windows Defender Backup on the Windows tab under "System". Compare this with the third image in my 26-Jun-2023 post <above> of the CCleaner v6.13.10517 interface.

CCleanerv6_15CustomCleanSystemWindowsDefendeBackupCheckboxGoneAug2023.png.1f3f64d87a090dfb8737dfe5ab3fde1c.png

There a <strong>Windows Defender</strong> checkbox on the Applications tab under "<strong>Utilities</strong>" but I don't know if this Windows Defender checkbox is new or if I just never noticed it before.  I have no idea what files it is supposed to clean because if if I enable that option and click Analyze it doesn't find anything to remove (<em>note that I use Microsoft Defender as my antivirus</em>).  <em>Note that the second image in my 26-Jun-2023 post &lt;<a href="<___base_url___>/topic/64975-windows-defender-backup-rule-not-working/?do=findComment&amp;comment=342848" rel="">above</a>&gt; shows I can use Windows 10's  built-in Disk Cleanup to clean non-essential Microsoft Defender files if I wish</em>,<em> and Disk Cleanup shows <strong>I currently have ~ 9.0 MB of Microsoft Defender files</strong> that could be removed that aren't being detected by CCleaner v6.15.</em>

If someone can't provide further insight I'll just leave that Windows Defender option unchecked.

CCleanerv6_15CustomCleanerUtitltiesWindowsDefenderNothingDetected24Aug2023.png.ac42aaf20b1fe72909b39b29f951fb21.png

-------------

Dell Inspiron 5584 * 64-bit Win 10 Pro v22H2 build 19045.3324 * Firefox v116.0.3 * Microsoft Defender v4.18.23070.1004-1.1.23070.1005 * Malwarebytes Premium v4.6.0.277-1.0.2114 * Macrium Reflect Free v8.0.7279 * CCleaner Free Portable v6.15.10623

[Windows Defender]
ID=2132
LangSecRef=3024
Detect=HKLM\SOFTWARE\Microsoft\Windows Defender
DetectFile=%ProgramFiles%\Microsoft AntiSpyware\GIANTAntiSpywareMain.exe
Default=False
FileKey1=%CommonAppData%\Microsoft\Windows Defender\Scans\History\Results\Quick|*.*
FileKey2=%CommonAppData%\Microsoft\Windows Defender\Scans\History\Results\Resource|*.*
FileKey3=%CommonAppData%\Microsoft\Windows Defender\Support|*.log
FileKey4=%CommonAppData%\Microsoft\Windows Defender\Scans\History\Service|*.log
FileKey5=%ProgramFiles%\Microsoft AntiSpyware|errors.log;tracksEraser.log;cleaner.log
SpecialKey1=N_WINDOWS_DEFENDER_QUARANTINE

It should be noted that I don't think I have any of these folders I have some of these folders but they don't open when i click. They say they're empty but I can't open not even as elevated UAC. I have Defender as my default and also have the defender that comes with Office 365

ok i opened them in elevated cmd prompt and they do have files. ccleaner is NOT cleaning these locations, possibly for the same reason they won't open in explorer

Thank you, @lmacri, for noticing those things. They'd both escaped my notice. And thank you, @Nergal, for that information. A fruitful thread, this.

I should note "controlled folder access" is turned off in defender settings.

11 hours ago, lmacri said:
<div class="ipsQuote_contents ipsClearfix" data-gramm="false">
	<p>
		If someone can't provide further insight I'll just leave that Windows Defender option unchecked.
	</p>
</div>

In my opinion "Windows Defender Backup" should never have been included in the first place, they are required 'just-in-case' files.

That's why they are protected and CCleaner wasn't able to clean them anyway,

As I recall the "Windows Defender" in "Utilities" clears out the Defender scan logs, (At least it used to, for me it doesn't seem to do anything at the moment).

If you clear out those logs then Defender thinks it has never been run, and wants/does a scan so that it has at least one scan log.