Solved A file is 'stuck' in quarantine


vranghel

New member
Local time
12:23 PM
Posts
24
OS
Windows 11
Hi everyone,

I'm encountering a problem that a lot of googling has not been able to solve:

While scanning my C: with WizTree, I noticed i have a 50GB file in C:\ProgramData\Microsoft\Windows Defender\Quarantine\ResourceData\07\0745A328E303B199BA9CFC64133C90B32C7866A3

I looked at what the file was and when it was quarantined using:
MpCmdRun.exe -restore -listall It was quarantined on 2023-10-25

I tried deleting it using the 'normal' way: Protection History > Filters> Quarantined Items but there is nothing showing up there.

I went to delete it manually but i don't have proper access to that folder - even though i'm admin

From this link from a previous thread (How to control Microsoft Defender Antivirus from PowerShell on Windows 11) I came across Get-MpPreference and did Set-MpPreference -QuarantinePurgeItemsAfterDelay 0

I'm not sure after how long the setting should take hold, but the file is still there.

My question is, how do i manually delete that quarantined file?

Thanks in advance!!
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    PC/Desktop
Try this. The reset option should delete the apps data.Use Option 3.
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 23H2 22631.3447
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Optiplex 7080
    CPU
    i9-10900 10 core 20 threads
    Motherboard
    DELL 0J37VM
    Memory
    32 gb
    Graphics Card(s)
    none-Intel UHD Graphics 630
    Sound Card
    Integrated Realtek
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    1tb Solidigm m.2 +256gb ssd+512 gb usb m.2 sata
    PSU
    500w
    Case
    MT
    Cooling
    Dell Premium
    Keyboard
    Logitech wired
    Mouse
    Logitech wireless
    Internet Speed
    so slow I'm too embarrassed to tell
    Browser
    Firefox
    Antivirus
    Defender+MWB Premium
  • Operating System
    Windows 10 Pro 22H2 19045.3930
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Optiplex 9020
    CPU
    i7-4770
    Memory
    24 gb
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    256 gb Toshiba BG4 M.2 NVE SSB and 1 tb hdd
    PSU
    500w
    Case
    MT
    Cooling
    Dell factory
    Mouse
    Logitech wireless
    Keyboard
    Logitech wired
    Internet Speed
    still not telling
    Browser
    Firefox
    Antivirus
    Defender+MWB Premium
I don't have Windows Security:
1704042048026.png

Nor did Get-AppxPackage *Microsoft.SecHealthUI* | Reset-AppxPackage work:
PS C:\Users\Vranghel> Get-AppxPackage *Microsoft.SecHealthUI* | Reset-AppxPackage
Reset-AppxPackage : The term 'Reset-AppxPackage' is not recognized as the name of a cmdlet, function, script file,
or operable program. Check the spelling of the name, or if a path was included, verify that the path is correct and
try again.
At line:1 char:43
+ Get-AppxPackage *Microsoft.SecHealthUI* | Reset-AppxPackage
+ ~~~~~~~~~~~~~~~~~~
+ CategoryInfo : ObjectNotFound: (Reset-AppxPackage:String) [], CommandNotFoundException
+ FullyQualifiedErrorId : CommandNotFoundException
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    PC/Desktop
I managed to run the 'Reset Windows Security app for All Users in PowerShell' :
Get-AppxPackage -AllUsers *Microsoft.SecHealthUI* | Reset-AppxPackage

and restarted, but the file is still there, and nothing appears under Protection History > Quarantined Items
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    PC/Desktop
Since nothing happened last time, i tried running the command 'Get-AppxPackage -AllUsers *Microsoft.SecHealthUI* | Reset-AppxPackage' making sure i'm in admin power shell, and this time i got an error:

PS C:\Users\Vrangel> Get-AppxPackage -AllUsers *Microsoft.SecHealthUI* | Reset-AppxPackage
Reset-AppxPackage : The term 'Reset-AppxPackage' is not recognized as the name of a cmdlet, function, script file, or operable program. Check the spelling of the name, or if a
path was included, verify that the path is correct and try again.
At line:1 char:53
+ ... et-AppxPackage -AllUsers *Microsoft.SecHealthUI* | Reset-AppxPackage
+ ~~~~~~~~~~~~~~~~~~
+ CategoryInfo : ObjectNotFound: (Reset-AppxPackage:String) [], CommandNotFoundException
+ FullyQualifiedErrorId : CommandNotFoundException

Not sure what's happening or what i'm doing wrong
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    PC/Desktop
I checked using TreeSize. Using that file path in programdata I have 3 zero byte files in Resource Data.(files all have 2digit names like yours) Uninstalling and reinstalling Defender should get rid of it but the methods I have used in the past to uninstall and reinstall Defender no longer work so hopefully someone will step in with a working method for 2023. @Brink, can you help?

I do know a surefire way of removing that file, but I do not know if there would be any repercussions by doing so.
I use one of the live Linux distros on usb, either Mint or Ubuntu. I boot into Linux and can remove any file in Windows I want. A 50 gb file is huge and I can't imagine what situation might have created it.
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 23H2 22631.3447
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Optiplex 7080
    CPU
    i9-10900 10 core 20 threads
    Motherboard
    DELL 0J37VM
    Memory
    32 gb
    Graphics Card(s)
    none-Intel UHD Graphics 630
    Sound Card
    Integrated Realtek
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    1tb Solidigm m.2 +256gb ssd+512 gb usb m.2 sata
    PSU
    500w
    Case
    MT
    Cooling
    Dell Premium
    Keyboard
    Logitech wired
    Mouse
    Logitech wireless
    Internet Speed
    so slow I'm too embarrassed to tell
    Browser
    Firefox
    Antivirus
    Defender+MWB Premium
  • Operating System
    Windows 10 Pro 22H2 19045.3930
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Optiplex 9020
    CPU
    i7-4770
    Memory
    24 gb
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    256 gb Toshiba BG4 M.2 NVE SSB and 1 tb hdd
    PSU
    500w
    Case
    MT
    Cooling
    Dell factory
    Mouse
    Logitech wireless
    Keyboard
    Logitech wired
    Internet Speed
    still not telling
    Browser
    Firefox
    Antivirus
    Defender+MWB Premium
The 50 GB file is a "Linux ISO" :wink: that has a false positive
1704044903400.png
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    PC/Desktop
Are you able to manually delete it from a command prompt at boot?


 

My Computers

System One System Two

  • OS
    Windows 11 Pro for Workstations
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom self build
    CPU
    Intel i7-8700K 5 GHz
    Motherboard
    ASUS ROG Maximus XI Formula Z390
    Memory
    64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz (F4-3600C18D-32GTZR)
    Graphics Card(s)
    ASUS ROG-STRIX-GTX1080TI-O11G-GAMING (11GB GDDR5X)
    Sound Card
    Integrated Digital Audio (S/PDIF)
    Monitor(s) Displays
    2 x Samsung Odyssey G75 27"
    Screen Resolution
    2560x1440
    Hard Drives
    1TB Samsung 990 PRO M.2,
    4TB Samsung 990 PRO M.2,
    8TB WD MyCloudEX2Ultra NAS
    PSU
    Seasonic Prime Titanium 850W
    Case
    Thermaltake Core P3 wall mounted
    Cooling
    Corsair Hydro H115i
    Keyboard
    Logitech wireless K800
    Mouse
    Logitech MX Master 3
    Internet Speed
    1 Gbps Download and 35 Mbps Upload
    Browser
    Google Chrome
    Antivirus
    Microsoft Defender and Malwarebytes Premium
    Other Info
    Logitech Z625 speaker system,
    Logitech BRIO 4K Pro webcam,
    HP Color LaserJet Pro MFP M477fdn,
    APC SMART-UPS RT 1000 XL - SURT1000XLI,
    Galaxy S23 Plus phone
  • Operating System
    Windows 11 Pro
    Computer type
    Laptop
    Manufacturer/Model
    HP Spectre x360 2in1 14-eu0098nr (2024)
    CPU
    Intel Core Ultra 7 155H 4.8 GHz
    Memory
    16 GB LPDDR5x-7467 MHz
    Graphics card(s)
    Integrated Intel Arc
    Sound Card
    Poly Studio
    Monitor(s) Displays
    14" 2.8K OLED multitouch
    Screen Resolution
    2880 x 1800
    Hard Drives
    2 TB PCIe NVMe M.2 SSD
    Internet Speed
    Intel Wi-Fi 7 BE200 (2x2) and Bluetooth 5.4
    Browser
    Chrome and Edge
    Antivirus
    Windows Defender and Malwarebytes Premium
I do know a surefire way of removing that file, but I do not know if there would be any repercussions by doing so.
I use one of the live Linux distros on usb, either Mint or Ubuntu. I boot into Linux and can remove any file in Windows I want. A 50 gb file is huge and I can't imagine what situation might have created it.
I have done the same since being able to have Linux Mint [since version13 now at 21] on a Desktop and creating the Bootable LiveUSB using its USB Image Writer.
 

My Computers

System One System Two

  • OS
    Win11 Pro RTM
    Computer type
    Laptop
    Manufacturer/Model
    Dell Vostro 3400
    CPU
    Intel Core i5 11th Gen. 2.40GHz
    Memory
    12GB
    Hard Drives
    256GB SSD NVMe
  • Operating System
    Windows 11 Pro RTM x64
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Vostro 5890
    CPU
    Intel Core i5 10th Gen. 2.90GHz
    Memory
    16GB
    Graphics card(s)
    Onboard, no VGA, using a DisplayPort-to-VGA adapter
    Monitor(s) Displays
    24" Dell
    Hard Drives
    512GB SSD NVMe, 2TB WDC HDD
    Browser
    Firefox, Edge
    Antivirus
    Windows Defender/Microsoft Security
leave it alone for now
 

My Computer

System One

  • OS
    Win11
    Computer type
    PC/Desktop
    Manufacturer/Model
    Asus Home built
    CPU
    i9-13900
    Motherboard
    ASUS Strix Z90-H
    Memory
    64 GB
    Graphics Card(s)
    Nvidia RTX 2080-ti
    Monitor(s) Displays
    Sony 55"
    Hard Drives
    SSD
    PSU
    850 watt EVGA
    Case
    Cooler Master Haf 932
    Keyboard
    MS
    Mouse
    MS
    Internet Speed
    100/100
    Antivirus
    Norton 360
The 50 GB file is a "Linux ISO"
Now you tell us. If you've created Linux installation usb media using the file, boot into the live distro and delete the file, BUT NOT THE FOLDER. However, it's doubtful that's all it is as no Linux iso is 50gb....unless you didn't deal with the file the first time it was detected and add the file to Defender exclusions as your should have. If it wasn't dealt with, maybe it kept detecting it over and over again somehow making that file in programdata larger each time.(that's a guess)

If you intend to keep the file, make sure it, or it's folder is added to exclusions or Defender will only create that big file again after it scans enough times..
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 23H2 22631.3447
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Optiplex 7080
    CPU
    i9-10900 10 core 20 threads
    Motherboard
    DELL 0J37VM
    Memory
    32 gb
    Graphics Card(s)
    none-Intel UHD Graphics 630
    Sound Card
    Integrated Realtek
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    1tb Solidigm m.2 +256gb ssd+512 gb usb m.2 sata
    PSU
    500w
    Case
    MT
    Cooling
    Dell Premium
    Keyboard
    Logitech wired
    Mouse
    Logitech wireless
    Internet Speed
    so slow I'm too embarrassed to tell
    Browser
    Firefox
    Antivirus
    Defender+MWB Premium
  • Operating System
    Windows 10 Pro 22H2 19045.3930
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Optiplex 9020
    CPU
    i7-4770
    Memory
    24 gb
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    256 gb Toshiba BG4 M.2 NVE SSB and 1 tb hdd
    PSU
    500w
    Case
    MT
    Cooling
    Dell factory
    Mouse
    Logitech wireless
    Keyboard
    Logitech wired
    Internet Speed
    still not telling
    Browser
    Firefox
    Antivirus
    Defender+MWB Premium
Something else. I have never had defender detect a legitimate Linux iso as erroneous. You might want to question the origin of that file. as it may have been altered.
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 23H2 22631.3447
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Optiplex 7080
    CPU
    i9-10900 10 core 20 threads
    Motherboard
    DELL 0J37VM
    Memory
    32 gb
    Graphics Card(s)
    none-Intel UHD Graphics 630
    Sound Card
    Integrated Realtek
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    1tb Solidigm m.2 +256gb ssd+512 gb usb m.2 sata
    PSU
    500w
    Case
    MT
    Cooling
    Dell Premium
    Keyboard
    Logitech wired
    Mouse
    Logitech wireless
    Internet Speed
    so slow I'm too embarrassed to tell
    Browser
    Firefox
    Antivirus
    Defender+MWB Premium
  • Operating System
    Windows 10 Pro 22H2 19045.3930
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Optiplex 9020
    CPU
    i7-4770
    Memory
    24 gb
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    256 gb Toshiba BG4 M.2 NVE SSB and 1 tb hdd
    PSU
    500w
    Case
    MT
    Cooling
    Dell factory
    Mouse
    Logitech wireless
    Keyboard
    Logitech wired
    Internet Speed
    still not telling
    Browser
    Firefox
    Antivirus
    Defender+MWB Premium
Something else. I have never had defender detect a legitimate Linux iso as erroneous. You might want to question the origin of that file. as it may have been altered.
I was being sarcastic that it's a Linux ISO. It is, however, an ISO obtained from the high seas.
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    PC/Desktop
Are you able to manually delete it from a command prompt at boot?


YES! It (finally) worked to delete it from the cmd at boot.

However, it was not smooth sailing:

First did this: del /f /s /q /a "C:\ProgramData\Microsoft\Windows Defender\Quarantine\ResourceData\07\0745A328E303B199BA9CFC64133C90B32C7866A3"

Path does not exist
I tried with X, same thing. Tried cd to ProgramData, them Microsoft etc....Quarantine folder did not exist

Then i tried diskpart which showed C Storage 2tb, and D NTFS which is ALL BACKWARDS!! C is the main one having 1 TB.
Why is that? I dont understand

Finally I did del /f /s /q /a "D:\ProgramData\Microsoft\Windows Defender\Quarantine\ResourceData\07\0745A328E303B199BA9CFC64133C90B32C7866A3"
and it worked, the file disappeared in WizTree

Thank you glasskuter, Brink and the rest.

Awesome community and guides for doing everything!!
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    PC/Desktop
If you are referring to the way disks are numbered (ie disk 0 or disk 1) don't worry about it. In some machines (my Dell being one of them)it depends on the disk configuration how the bios numbers them. In my particular case I have an m.2 system drive and a HDD storage drive. I have found if a sata drive is connected it is disk 0. I can disconnect the HDD and the m.2 becomes disk 0. I can connect a second sata HDD or SSD it becomes disk 1 and the m.2 becomes disk 2. I gave up trying to figure it out but get irritated every time I see it. Out of years of habit I expect my system drive to be disk 0 NO MATTER WHAT. Not always so any more..

Glad you got rid of that big file and regained your disk space.
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 23H2 22631.3447
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Optiplex 7080
    CPU
    i9-10900 10 core 20 threads
    Motherboard
    DELL 0J37VM
    Memory
    32 gb
    Graphics Card(s)
    none-Intel UHD Graphics 630
    Sound Card
    Integrated Realtek
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    1tb Solidigm m.2 +256gb ssd+512 gb usb m.2 sata
    PSU
    500w
    Case
    MT
    Cooling
    Dell Premium
    Keyboard
    Logitech wired
    Mouse
    Logitech wireless
    Internet Speed
    so slow I'm too embarrassed to tell
    Browser
    Firefox
    Antivirus
    Defender+MWB Premium
  • Operating System
    Windows 10 Pro 22H2 19045.3930
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Optiplex 9020
    CPU
    i7-4770
    Memory
    24 gb
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    256 gb Toshiba BG4 M.2 NVE SSB and 1 tb hdd
    PSU
    500w
    Case
    MT
    Cooling
    Dell factory
    Mouse
    Logitech wireless
    Keyboard
    Logitech wired
    Internet Speed
    still not telling
    Browser
    Firefox
    Antivirus
    Defender+MWB Premium
It looked like this:

Volume 0 C Storage NTFS
Volume 1 D NTFS

The weird part is that D is Storage and C is the main windows drive and partition- i have 1 separate drive for each
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    PC/Desktop
What does disk management say?
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 23H2 22631.3447
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Optiplex 7080
    CPU
    i9-10900 10 core 20 threads
    Motherboard
    DELL 0J37VM
    Memory
    32 gb
    Graphics Card(s)
    none-Intel UHD Graphics 630
    Sound Card
    Integrated Realtek
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    1tb Solidigm m.2 +256gb ssd+512 gb usb m.2 sata
    PSU
    500w
    Case
    MT
    Cooling
    Dell Premium
    Keyboard
    Logitech wired
    Mouse
    Logitech wireless
    Internet Speed
    so slow I'm too embarrassed to tell
    Browser
    Firefox
    Antivirus
    Defender+MWB Premium
  • Operating System
    Windows 10 Pro 22H2 19045.3930
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Optiplex 9020
    CPU
    i7-4770
    Memory
    24 gb
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    256 gb Toshiba BG4 M.2 NVE SSB and 1 tb hdd
    PSU
    500w
    Case
    MT
    Cooling
    Dell factory
    Mouse
    Logitech wireless
    Keyboard
    Logitech wired
    Internet Speed
    still not telling
    Browser
    Firefox
    Antivirus
    Defender+MWB Premium

My Computers

System One System Two

  • OS
    Windows 11 Pro 23H2 22631.3447
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Optiplex 7080
    CPU
    i9-10900 10 core 20 threads
    Motherboard
    DELL 0J37VM
    Memory
    32 gb
    Graphics Card(s)
    none-Intel UHD Graphics 630
    Sound Card
    Integrated Realtek
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    1tb Solidigm m.2 +256gb ssd+512 gb usb m.2 sata
    PSU
    500w
    Case
    MT
    Cooling
    Dell Premium
    Keyboard
    Logitech wired
    Mouse
    Logitech wireless
    Internet Speed
    so slow I'm too embarrassed to tell
    Browser
    Firefox
    Antivirus
    Defender+MWB Premium
  • Operating System
    Windows 10 Pro 22H2 19045.3930
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Optiplex 9020
    CPU
    i7-4770
    Memory
    24 gb
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    256 gb Toshiba BG4 M.2 NVE SSB and 1 tb hdd
    PSU
    500w
    Case
    MT
    Cooling
    Dell factory
    Mouse
    Logitech wireless
    Keyboard
    Logitech wired
    Internet Speed
    still not telling
    Browser
    Firefox
    Antivirus
    Defender+MWB Premium
So this is weird
Diskpart in windows:
1704107632766.png


Diskpart in boot cmd
1704107694024.png
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    PC/Desktop
But what does disk management say?
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 23H2 22631.3447
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Optiplex 7080
    CPU
    i9-10900 10 core 20 threads
    Motherboard
    DELL 0J37VM
    Memory
    32 gb
    Graphics Card(s)
    none-Intel UHD Graphics 630
    Sound Card
    Integrated Realtek
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    1tb Solidigm m.2 +256gb ssd+512 gb usb m.2 sata
    PSU
    500w
    Case
    MT
    Cooling
    Dell Premium
    Keyboard
    Logitech wired
    Mouse
    Logitech wireless
    Internet Speed
    so slow I'm too embarrassed to tell
    Browser
    Firefox
    Antivirus
    Defender+MWB Premium
  • Operating System
    Windows 10 Pro 22H2 19045.3930
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Optiplex 9020
    CPU
    i7-4770
    Memory
    24 gb
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    256 gb Toshiba BG4 M.2 NVE SSB and 1 tb hdd
    PSU
    500w
    Case
    MT
    Cooling
    Dell factory
    Mouse
    Logitech wireless
    Keyboard
    Logitech wired
    Internet Speed
    still not telling
    Browser
    Firefox
    Antivirus
    Defender+MWB Premium

Latest Support Threads

Back
Top Bottom