Additional Microsoft Defender tools and services that provide security across various platforms and environments
A recurring detection usually means the malware was only partially removed or another hidden component is reinstalling it after startup or restart.
A failed firmware update is not supported as the likely cause here. The firmware-related content available is about how firmware is updated or analyzed, not about causing repeated Defender trojan detections. Repeated detections are specifically described as commonly being caused by a hidden malware component or by revisiting the malicious source.
Recommended cleanup path:
- Run the Windows Malicious Software Removal Tool full scan.
- Press Windows key + R.
- Run %windir%\system32\mrt.exe.
- Select Yes if prompted.
- Follow the prompts to scan and clean the PC.
- Restart the PC.
- Manually install the latest updates.
- Run Microsoft Defender Offline if the same threat keeps returning.
- Save all work first because the PC will restart.
- Go to Start > Settings > Update & Security > Windows Security > Virus & threat protection.
- Under Current threats, select Scan options.
- Select Windows Defender Offline scan > Scan now.
- Avoid the original download source or email attachment if one is suspected, because malware can return if it is downloaded again.
- If Defender reports the threat as partially removed, use the advanced malware troubleshooting guidance and Defender Offline as the next step.
Trojans commonly download other malware, record activity, steal credentials, or give an attacker control of the device, so repeated detections should be treated as a serious compromise.
References: