Share via

Malicious Software Removal Tool says infections found -- then, says nothing found!

Anonymous
2024-09-02T18:21:39+00:00

I'm running win10.

I manually ran the Malicious Software Removal Tool on my computer. Version: 5.127.24080.1001

I chose "Full Scan," which took several hours to complete.

During the scan, the tool showed 3 infected files on my computer. After the scan, the tool (apparently) shut down my computer. (I say "apparently" only because the computer had, in fact, been shut down. I can only assume the tool did this.)

I was still curious to see which files had been infected, and with what. So, to see the scan results, I went to: %windir%\debug\mrt.log

The log gave the following:

---------------------------------------------------------------------------------------

Microsoft Windows Malicious Software Removal Tool v5.127, (build 5.127.24080.1001)

Started On Sun Sep 1 17:33:22 2024


Engine: 1.1.24060.5

Signatures: 1.415.222.0

MpGear: 1.1.16330.1

Run Mode: Interactive Graphical Mode


Results Summary:

----------------

No infection found.

So, . . . HUH?! It clearly identifed 3 files infected during the scan, but in the report log, it says that nothing was found.

Anyone have an idea why this is so?

Thanks!

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
  1. EmilyS726 225.5K Reputation points Independent Advisor
    2024-09-02T20:26:34+00:00

    Hello, this is Emily.

    This behavior is actually completely normal as long a internet remained connected the whole time.

    All of the findings during the scan are potential/suspicious ones. Think of it as the scanner are marking those so that at the final phase (which requires internet), it can check them against virus definition. This is where the scanner will perform a MAPS (Microsoft Active Protection Service" request to connect to the cloud server, and to upload these initial findings for confirmation. This is why you received a different total number at the end. If it came back with nothing, it means the scan went through finding no threats.

    1 person found this answer helpful.
    0 comments No comments

0 additional answers

Sort by: Most helpful