Trojan Virus detected while scanning.

Toko Aoi 0 Reputation points
2026-06-19T06:30:30.11+00:00

Screenshot of scan report The Windows Defender Offline Scan detected a trojan running on PowerShell. What should I do now?

Microsoft Security | Microsoft Defender | Other
0 comments No comments

1 answer

Sort by: Newest
  1. AI answer

    2026-06-19T06:31:03.0266667+00:00

    Based on the screenshot, Microsoft Defender Offline has already detected and removed the trojan (status: Threat removed or restored). Next steps are to confirm the system is clean and harden it against reinfection:

    1. Confirm the threat action in Protection history
      • Open Windows SecurityVirus & threat protectionProtection history.
      • Locate the trojan entry and verify the action is Removed or Quarantined. If any item shows Allowed or No action, select it and choose to Remove or Quarantine.
    2. Run another scan from Windows
      • In Windows SecurityVirus & threat protectionScan options, run a Full scan to check all files.
      • If malware keeps being detected again after reboots, run another Microsoft Defender Antivirus (offline scan) from the same Scan options page to catch hidden components that may reinstall the trojan.
    3. Use Microsoft Defender Offline when malware persists
      • If the same or similar trojan keeps coming back, start an offline scan:
        • StartSettingsUpdate & SecurityWindows SecurityVirus & threat protectionScan optionsWindows Defender Offline scanScan now.
      • The PC restarts, runs the offline scan in the Windows Recovery Environment, and restarts again.
      • Afterward, open Windows SecurityProtection history to review and ensure all detected items have been removed.
    4. Keep Windows and definitions updated
      • Install the latest Windows updates and ensure Microsoft Defender Antivirus definitions are up to date so new trojan variants are detected quickly.
    5. Prevent reinfection
      • Avoid downloading or running unknown scripts or tools, especially those that launch PowerShell.
      • Use Microsoft Edge with Microsoft Defender SmartScreen to help block malicious sites and downloads.

    If Windows Security ever reports a threat as partially removed, follow the guidance to run the Malicious Software Removal Tool and then a Microsoft Defender Offline scan to complete cleanup.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

    1 person found this answer helpful.

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.