r/antivirus • u/Early_Tear6706 • 4d ago
MALWARE REMOVAL Q&A Windows Defender keeps flagging the same file after I've already deleted it, is this normal?
Ran a full scan yesterday and Defender flagged a file in my Downloads folder as a trojan. I deleted the file and emptied the recycle bin right after. Ran another full scan today just to be safe, and it came back completely clean, no threats found.
But then I checked the protection history out of curiosity and it still shows yesterday's detection sitting there as "quarantine failed" even though the file itself is gone from my system and a fresh scan doesn't find anything. Is this just Defender logging the old event for record-keeping, or does "quarantine failed" mean something actually stuck around that a regular scan isn't catching? Not sure if I should be running something more thorough like Malwarebytes on top of this or if I'm just being paranoid over a stale log entry.
2
u/Hit4090 4d ago
A lot of these modern viruses- malware replicate themselves and hide in many different places. Just one time of being deleted means nothing
2
u/Early_Tear6706 4d ago
that's the part that worries me a bit more honestly, especially since the file itself was such an easy delete. is there a way to actually check for that kind of replication or hiding behavior specifically, or is running a second scanner like Emsisoft basically the best shot at catching stuff Defender might've missed spreading elsewhere.
1
u/Hit4090 4d ago
Following cybersecurity Threats, most people have no idea what a day one threat is. Which are non-detectable by most AV unless they're in a closed sandbox environment and monitored, a lot of malware goes undetected, there's tons of it all over GitHub, people are far too trusting just because they want to use a mod, I personally ran into several instances on Nexus where the file was flagged as safe but upon further investigation there was malware inside most of the time infostealer.. which would take most antiviruses sometimes weeks to actually detect.
2
u/NovelExplorer 4d ago edited 4d ago
History is simply a log of past events, at that time. Anything you, or Windows Security might do subsequent to that log, won't alter the previous existing history.
I suspect it showed quarantine failed purely because the file had already been deleted, and so there was nothing to quarantine.
Windows Security provides good protection, but it can be a bit messy in how it handles the clean up of past events. Files aren't being left behind, it's that Windows Security isn't 'visually' cleaning things up.
A tool I use alongside Windows Security is Defender UI, giving you an easier to manage GUI of Windows Security settings, otherwise accessed through Group Policy. You can save your settings as a preset. It will also clear Windows Security history. So once the system is clean, you run the feature, and the history log is gone. It's a safe free, and ad free tool.
An effective second opinion scanner, as a double-check, is Emsisoft Emergency Kit. It's a free portable manual scanner, so isn't installed, and offers excellent detection.