Additional Microsoft Defender tools and services that provide security across various platforms and environments
Based on the screenshot, Microsoft Defender Offline has already detected and removed the trojan (status: Threat removed or restored). Next steps are to confirm the system is clean and harden it against reinfection:
- Confirm the threat action in Protection history
- Open Windows Security → Virus & threat protection → Protection history.
- Locate the trojan entry and verify the action is Removed or Quarantined. If any item shows Allowed or No action, select it and choose to Remove or Quarantine.
- Run another scan from Windows
- In Windows Security → Virus & threat protection → Scan options, run a Full scan to check all files.
- If malware keeps being detected again after reboots, run another Microsoft Defender Antivirus (offline scan) from the same Scan options page to catch hidden components that may reinstall the trojan.
- Use Microsoft Defender Offline when malware persists
- If the same or similar trojan keeps coming back, start an offline scan:
- Start → Settings → Update & Security → Windows Security → Virus & threat protection → Scan options → Windows Defender Offline scan → Scan now.
- The PC restarts, runs the offline scan in the Windows Recovery Environment, and restarts again.
- Afterward, open Windows Security → Protection history to review and ensure all detected items have been removed.
- If the same or similar trojan keeps coming back, start an offline scan:
- Keep Windows and definitions updated
- Install the latest Windows updates and ensure Microsoft Defender Antivirus definitions are up to date so new trojan variants are detected quickly.
- Prevent reinfection
- Avoid downloading or running unknown scripts or tools, especially those that launch PowerShell.
- Use Microsoft Edge with Microsoft Defender SmartScreen to help block malicious sites and downloads.
If Windows Security ever reports a threat as partially removed, follow the guidance to run the Malicious Software Removal Tool and then a Microsoft Defender Offline scan to complete cleanup.
References: