If the same trojans are detected again after each restart, the most likely issue is recurring malware or a hidden component reinstalling it.
Recommended steps:
- In Windows Security, review the detection and choose Clean computer if prompted.
- Show details lets the available actions be selected:
- Remove: permanently deletes the file
- Quarantine: moves it to a safe location so it cannot run
- Allow: lets it run and stops future alerts; use this only if the software and publisher are trusted
- Make sure Microsoft Defender Antivirus is fully updated before scanning:
- Go to Start > Settings > Update & Security > Windows Security > Virus & threat protection
- Under Virus & threat protection updates, select Check for updates
- Under Threat definitions, select Check for updates
- Turn on these protection features if they were disabled:
- Cloud-delivered protection
- Automatic sample submission
- Path: Start > Settings > Update & Security > Windows Security > Virus & threat protection > Manage settings
- Run a Microsoft Defender Offline scan. This is the key step when malware keeps coming back after reboot.
- Warning: the PC will restart before the scan starts, so save all work first.
- Go to Start > Settings > Update & Security > Windows Security > Virus & threat protection
- Under Current threats, select Scan options
- Select Windows Defender Offline scan
- Select Scan now
- Avoid reopening the source of the infection after cleanup, such as suspicious downloads, websites, or email attachments, because the malware can be reintroduced.
- If suspicious files still are not detected or the detections appear incorrect, submit the file to Microsoft for analysis: Submit a file for malware analysis.
If scans also fail or produce errors, run Windows Update and then try the scan again.
References: