Question Microsoft Defender found Trojans on my PC

Tommy Sawyer

Commendable
Aug 20, 2021
124
14
1,595
I found some trojans on my computer, and defender removed two and blocked one. What do you think I should do? I running the scan again to check? seems like they were located in my photos files. and users/appdata/local/packages. Would you do system restore or would you do a whole backup from my macrium reflect about a month ago?

Trojan:Win32/Jpgiframe.A
Trojan:Script/Wacatac.B!ml
Trojan:Win32/Ursnif!ml
 

Tommy Sawyer

Commendable
Aug 20, 2021
124
14
1,595
Turn off system restore as some times things hide there, then you can enable it again and create a new restore point.

Scan with malwarebytes as well. Windows defender if I recall also has a boot scan function that will intercept the boot of the pc. May run that then see if it finds anything else.
I ran one more time and another came up with a different name ... similar
Trojan:Script/Wacatac.H!ml
still in the AppData/Local/Packages/microsoftcommunicationsapps

When do you know if you got them all? Also, why do I get to block some and remove some with defender?
two removed and one blocked.
 
You don’t really without a reformat. I would run a scan with malwarebytes. I think Sophos has a free tool called clean and scan, so I might run a scan with that also. Then I’d also at least run a boot scan with windows defender and see if things come up clean. If not then you probably need to consider a clean wipe as sometimes that’s the one way to be sure.
 
Looking back here are a few other things you could run if you feel like it. Been a while since I did a lot of cleanups but the strategy I think would be to try to run at least 4-5 different scans of different products. If you see that all of them seem to agree the system is clean then you can maybe have some degree of comfort but obviously there’s a point where a reformat is necessary.

 
  • Like
Reactions: Tommy Sawyer