Please open Command Prompt (admin) and run these commands:
reagentc /info
dir C:\Windows\system32\Recovery /a
dir C:\Recovery /s /a
Copy the output to a text file and upload it in your next reply.
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
I've run other antivirus (Malwarebytes, Hitman Pro, ESet) with no findings save for when ESet found a trace (tracking cookie) from Microsoft Edge- a browser I do not use. I am unclear if the trojan is a false positive, but as I am unable to run an Offline Scan due to the page defaulting to the Boot Menu, it would not be unwise to treat it as a genuine positive.
I had to reboot from an ISO at the beginning of August related to my attempts to find what was consuming my memory and causing my fans to overheat. The current hypothesis that the Win11 update had caused issues; after a stepdown to Win10, the issues appear to be solved. However, the ISO was from a desktop and I needed to surplant missing functions (i.e. touchpad device drivers) from other sources.
The trojan itself only appears after a Windows Defender Offline Scan is attempted, and only appears with a Microsoft Windows Defender Full Scan. Once quarantined and removed/restored, it does not trigger a response from the scans.
Please advise.
EDIT [09.01.26: 2038] : Ran the Malicious Software Removal Tool Quick Scan- no threat detected. Running Full Scan, will report back with results.
EDIT [09.01.26: 2318] : Ran the Malicious Software Removal Tool Quick Scan twice to the same result. Please advise.
Please open Command Prompt (admin) and run these commands:
reagentc /info
dir C:\Windows\system32\Recovery /a
dir C:\Recovery /s /a
Copy the output to a text file and upload it in your next reply.
AI answer
Treat this as a remediation issue first, not proof by itself that active malware is still running.
Supported facts from Microsoft guidance:
Given the described behavior — the detection appears only after attempting an Offline Scan, then shows up on a Full Scan, and after quarantine/removal it no longer appears — the practical next steps are:
Windows key + R%windir%\system32\mrt.exeBecause the detected path is C:\Recovery\WindowsRE\ReAgent.xml->(UTF-8), use caution before deleting anything under C:\Recovery. That location is related to Windows Recovery, so deletion could affect recovery features. Prefer scanning first, then use Microsoft’s advanced troubleshooting path if the detection keeps returning.
References: