Jump to content

Trojan (as per Microsoft Defender)


Recommended Posts

Hello, I am on Windows 11.  Microsoft Defender is my AV.
I also use Malwarebytes / Windows malware removal tool (MRT).

Recently, Defender flagged a file as containing trojan and quarantined it.
I have a feeling that it could be a false positive.

I am attaching the file, if it could be analysed please.

Defender is not allowing me to open the "infected" subfolder inside, viz., "PP2021".

Thank you


Edited by shadowwar
Link to post
Share on other sites

This is what I could get from Defender ... screenshot attached.

The first incident of "detection" is expanded, with two choices ... Restore or Remove.
Thereafter, when I have tried to access the subfolder, Defender has logged it.


Link to post
Share on other sites

Rich Matteo, following an advise in Microsoft Community forum, I did submit the file to them.

It seems that they have a semi-automated process.
I was advised to change the password to "infected".  Could not do that, as even after purportedly the "trojan" being quarantined by Defender, I could not access the files in the subfolder to change the password.

I understand a bit of technical stuff, if in simple language.
Could you please tell me what exactly happens when AV has quarantined the "malware" (FP, say). And, if I ask Defender to restore the "offensive" stuff, what happens ? Does Defender unshackle the contents of the "problem subfolder" ?

Would love to learn a bit.
Thank you

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.