Unable to remove a Virus using Defender

Hello

I recently found a old USB drive and I connected it to my PC. Then I ran a scan through Defender and it showed a threat. When I tried to remove it, it didn't remove. Then I did a Microsoft offline scan but before reaching 100% scan my pc restarted. How will I know whether it affected my pc or it just affected the USB drive? And I need a solution to remove the virusImage

|
Answer
Answer
Hello, I'm Quinn, and I'm happy to help.

To know if your PC was affected, here's how:
1. Check active processes in Task Manager, press Ctrl + Shift + Esc to open Task Manager.
2. Go to the Processes tab.
3. Look for any unusual or unknown processes running, especially .bat, .vbs, or .exe files you don’t recognize.
4. If you find anything suspicious, right-click > Open file location. If it leads to a hidden system folder, your PC is likely infected.
5. Check Suspicious Startup Programs, after checking the processing tab, now go to the Startup tab.
6. Look for unknown programs that start automatically with Windows.
7. If you see anything unfamiliar, disable it by right-clicking and selecting Disable.

Next,
1. Let's check in the registry, press Win + R, type "regedit", and hit Enter.
2. Navigate to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run

3. Look for unknown entries, especially anything referencing .bat, .exe, or .vbs files. Do not delete anything unless you are sure it’s malware. If you find something suspicious, kindly take a screenshot and let me know.

Next, since the scan was interrupted, you should manually run a Full Scan in Safe Mode and use Malwarebytes for additional scanning. Let's boot into Safe Mode, this makes it easier to detect and remove threats like Worm:BAT/Autorun.AI, which may be actively running in normal mode and interfering with scans.

Before going to safe mode, download Malwarebytes https://www.malwarebytes.com/ , and don't worry it's free from Malwarebytes.
[Note: This is a non-Microsoft website. The page appears to be providing accurate, safe information. Watch out for ads on the site that may advertise products frequently classified as a PUP (Potentially Unwanted Products). Thoroughly research any product advertised on the site before you decide to download and install it.]

Once done, proceed with the step-by-step.

1. Press Win + R, type "msconfig", and hit Enter.
2. Go to the Boot tab.
3. Check Safe Boot > Select Minimal > Click OK and restart.
4. Run a Full Scan with Windows Defender: Open Windows Security > Virus & Threat Protection > Full Scan. Remove detected threats.
5. Once the full scan is done, open Malwarebytes.
6. Install it and run a Full Scan.
7. Delete any detected threats.
8. Then try running Microsoft Defender Offline Scan Again.

If the scan fails again, malware may still be interfering, and a deeper cleaning method is required.

Once you're done with the PC, let's clean the USB Drive (Without Deleting Files)
1. Plug in the USB, but DO NOT Open It in File Explorer.
2. In the search bar, type "Command Prompt" and run it as administrator.
3. Type the following to unhide files and remove malware attributes:

attrib -h -r -s /s /d D:\*

(Replace D: with your USB drive letter.)

4. Now, let's scan the USB with Windows Defender: Open Windows Security > Virus & Threat Protection> Custom Scan. Select the USB drive and scan it.
5. After the scan, open Malwarebytes and perform a Custom Scan on the USB.
6. Final Option (If Virus Persists): If malware keeps coming back, back up important files and format the USB (Right-click > Format).

However, if there are no important files on the USB.
1. Plug in the USB but DO NOT open it in File Explorer.
2. Open File Explorer, right-click on the USB drive, and select Format.
3. Choose:
File System: NTFS (for Windows only) or FAT32 (for compatibility with other devices).
Quick Format: Unchecked (for a full wipe, recommended for virus removal).

4. Click Start, then OK to confirm.
5. After formatting, the USB will be 100% clean.
6. Run a quick Windows Defender scan on it to ensure it’s safe.

Please keep me posted.

1 person found this reply helpful

·

Was this reply helpful?

Sorry this didn't help.

Great! Thanks for your feedback.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this reply?

Thanks for your feedback.

 
 

Question Info


Last updated April 17, 2025 Views 75 Applies to: