Additional Microsoft Defender tools and services that provide security across various platforms and environments
The behavior described matches active malware, and the repeated re‑detection of the same trojan indicates it is likely being reinstalled by a hidden component. Use Microsoft’s built‑in tools and an offline scan to clean it, then harden the device and browser.
- Disconnect and prepare
- Keep the device disconnected from the internet while cleaning.
- Save open work because some steps will restart the PC.
- Run a full Microsoft Defender scan
- Open Windows Security → Virus & threat protection.
- Select Scan options → Full scan and let it complete.
- Follow any remediation steps (quarantine/remove) that Defender recommends.
- Run Microsoft Defender Offline (to stop the trojan from coming back) When malware keeps reappearing, Microsoft recommends an offline scan because a hidden component can reinstall it as soon as Windows starts.
To start an offline scan in Windows:
- Select Start > Settings > Update & Security > Windows Security > Virus & threat protection.
- Under Current threats, select Scan options.
- Select Windows Defender Offline scan and then Scan now.
The PC will restart and run a deep scan before Windows loads, which helps detect and remove components that hide during normal operation.
- Update Windows and security tools
- Run Windows Update and install all important/security updates. This helps close vulnerabilities that malware can exploit.
- Ensure Microsoft Defender Antivirus is up to date and real‑time protection is turned on.
- Check for recurring symptoms After the offline scan and updates:
- Reconnect to the internet.
- Open the browser and monitor for:
- New tabs opening by themselves
- Random typing
- Search engine changing without consent If any of these reappear, run another Defender scan immediately.
- Reduce the chance of reinfection
- Avoid unsafe sites (especially illegal download/torrent sites) and suspicious email attachments or links.
- Use a modern browser such as Microsoft Edge with Microsoft Defender SmartScreen enabled to block known malicious sites.
- Consider clearing or reviewing browser extensions and removing anything not recognized or not needed.
If, after an offline scan and updates, the trojan still reappears, consider backing up important files and performing a clean Windows reinstall as a last resort to ensure all hidden components are removed.
References: