P
Pratham Shanbhag
Guest
Hello.
My son connected a pen drive to my laptop which had GandCrab.AF Trojan and tiggre!plock yesterday. Windows defender detected it and deleted all the files of the pen drive. My son "allowed" these trojans and connected to the internet. I immediately disconnected it from the internet and windows defender showed me that it had quarantined the viruses but it would not in the future. I immediately blocked them again but Windows Defender seems to keep telling that I have a threat and actions are required.
I click Start Actions but nothing happens. It keeps showing me the same message. Under threat history, it shows that multiple copies of the viruses have been blocked except one: Trojan Win32/GandCrab.AF. Files affected being winsvc.exe. It shows "Active" and "Acions Required" but does not do anything when click "Remove" or "Quarantine". The other copies which defender blocked showed that it had affected registry files (but was blocked by Defender).
I even tried running Windows Defender Offline Scan and the threat error still shows up. Full scans have also been performed.
My questions are: 1--Has Windows Defender itself been affected since the threats were allowed earlier?
2--Has the virus been removed but Defender is showing a false positive?
3--How do I get rid of the virus if it really is present on my system?
Thank you.
More...
My son connected a pen drive to my laptop which had GandCrab.AF Trojan and tiggre!plock yesterday. Windows defender detected it and deleted all the files of the pen drive. My son "allowed" these trojans and connected to the internet. I immediately disconnected it from the internet and windows defender showed me that it had quarantined the viruses but it would not in the future. I immediately blocked them again but Windows Defender seems to keep telling that I have a threat and actions are required.
I click Start Actions but nothing happens. It keeps showing me the same message. Under threat history, it shows that multiple copies of the viruses have been blocked except one: Trojan Win32/GandCrab.AF. Files affected being winsvc.exe. It shows "Active" and "Acions Required" but does not do anything when click "Remove" or "Quarantine". The other copies which defender blocked showed that it had affected registry files (but was blocked by Defender).
I even tried running Windows Defender Offline Scan and the threat error still shows up. Full scans have also been performed.
My questions are: 1--Has Windows Defender itself been affected since the threats were allowed earlier?
2--Has the virus been removed but Defender is showing a false positive?
3--How do I get rid of the virus if it really is present on my system?
Thank you.
More...