Windows Microsoft Defender identifying "Trojan:XML/GreatXML.GVA!MTB" in C:\Recovery\WindowsRE\ReAgent.xml->(UTF-8)

B V 0 Reputation points
2026-09-02T00:31:59.41+00:00

I've run other antivirus (Malwarebytes, Hitman Pro, ESet) with no findings save for when ESet found a trace (tracking cookie) from Microsoft Edge- a browser I do not use. I am unclear if the trojan is a false positive, but as I am unable to run an Offline Scan due to the page defaulting to the Boot Menu, it would not be unwise to treat it as a genuine positive.

I had to reboot from an ISO at the beginning of August related to my attempts to find what was consuming my memory and causing my fans to overheat. The current hypothesis that the Win11 update had caused issues; after a stepdown to Win10, the issues appear to be solved. However, the ISO was from a desktop and I needed to surplant missing functions (i.e. touchpad device drivers) from other sources.

The trojan itself only appears after a Windows Defender Offline Scan is attempted, and only appears with a Microsoft Windows Defender Full Scan. Once quarantined and removed/restored, it does not trigger a response from the scans.

Please advise.

Screenshot 2026-09-01 203312

EDIT [09.01.26: 2038] : Ran the Malicious Software Removal Tool Quick Scan- no threat detected. Running Full Scan, will report back with results.

EDIT [09.01.26: 2318] : Ran the Malicious Software Removal Tool Quick Scan twice to the same result. Please advise.
User's image

Windows for home | Windows 10 | Security and privacy

2 answers

Sort by: Newest
  1. Ramesh 180.9K Reputation points Volunteer Moderator
    2026-09-02T03:42:00.39+00:00

    Please open Command Prompt (admin) and run these commands:

    reagentc /info
    
    dir C:\Windows\system32\Recovery /a
    
    dir C:\Recovery /s /a
    

    Copy the output to a text file and upload it in your next reply.

    Was this answer helpful?

    1 person found this answer helpful.

  2. AI answer

    2026-09-02T00:32:19.8533333+00:00

    Treat this as a remediation issue first, not proof by itself that active malware is still running.

    Supported facts from Microsoft guidance:

    • A detection marked as only partially removed means some malware components were cleaned, but not all of them may have been removed.
    • Some Microsoft Defender Antivirus remediations require a reboot to complete.
    • If the same malware is detected again after restart, a hidden component can be reinstalling it, and Microsoft recommends Microsoft Defender Offline.
    • If a threat cannot be remediated, it can be because it is inside a compressed file or network location, and a manual scan or deletion of the file may be required.

    Given the described behavior — the detection appears only after attempting an Offline Scan, then shows up on a Full Scan, and after quarantine/removal it no longer appears — the practical next steps are:

    1. Run the Malicious Software Removal Tool.
      • Press Windows key + R
      • Run: %windir%\system32\mrt.exe
      • Allow it to make changes if prompted
      • Follow the prompts to scan and clean the PC
    2. Restart the PC.
      • This matters because Defender remediation can require a reboot to finish.
    3. Install the latest Windows updates.
      • Microsoft specifically recommends restarting and then manually installing the latest updates after partial removal.
    4. If the detection returns after restart, run Microsoft Defender Offline again.
      • Path: Start > Settings > Update & Security > Windows Security > Virus & threat protection > Current threats > Scan options > Windows Defender Offline scan > Scan now
      • Save work first, because the PC restarts before the scan.
    5. If Defender reports the threat cannot be remediated, manually inspect and scan or remove the affected item.
      • Microsoft guidance for unremediated threats is to browse to the detected file and either delete it or right-click it and choose Scan with Windows Defender.
      • A full scan is also recommended if the file origin is uncertain.
    6. If Defender keeps encountering scan or removal errors, run Windows Update and, if needed, manually install the latest protection updates.
    7. If the file was incorrectly classified, submit it to Microsoft for malware analysis as a false positive.
      • Microsoft provides a file submission process for false positives and false negatives.
    8. If the issue persists, use Microsoft’s advanced malware troubleshooting guidance.

    Because the detected path is C:\Recovery\WindowsRE\ReAgent.xml->(UTF-8), use caution before deleting anything under C:\Recovery. That location is related to Windows Recovery, so deletion could affect recovery features. Prefer scanning first, then use Microsoft’s advanced troubleshooting path if the detection keeps returning.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.