Share via

Microsoft Windows Malicious Software Removal tool - Nov. 2017 is stuck on powershell.exe

Anonymous
2017-12-11T06:01:55+00:00

Microsoft Windows Malicious Software Removal tool - Nov. 2017 is stuck on powershell.exe and is stuck there for 9 hours now.  The scan shows 503 infected files.  After hours more, scan finished and said no infected files found.   Did the scan again, and the same thing is happening.  The debug file shows many many errors.  I did the SafetyScan, and nothing was found.  I have windows 10 on a Dell Latitude e6410.  Windows defender finds nothing.  Someone, pls help...

Thanks.....don

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

Answer accepted by question author

Anonymous
2017-12-11T16:25:43+00:00

The MSRT seems to be misbehaving for lots of people lately, and the real question isn’t how to fix the bugs (we can’t) – it’s whether it really makes any sense to be scanning with this relic malware-removal tool. The MSRT was a stopgap solution for people on older operating systems that might not be heeding the Security Center’s warning to install a real-time AV app – and this tool can only detect a small number of prevalent threats.

But now that we have Windows Defender Antivirus included in Windows 10, you should just be running occasional Full Scans with Windows Defender itself. Windows Defender uses the full set of Microsoft definitions, rather than just the small subset included with the MSRT – and it’s available for all Windows 10 users. If you’re using a third-party AV solution for your real-time protection, then all you have to do is enable Windows Defender’s Limited Periodic Scanning mode, and this will allow you to run Full Scans with Windows Defender (as well as with your third-party AV app). Limited Periodic Scanning also allows you to run scans with Windows Defender Offline, which runs outside of the Windows environment so that malware can’t hide by manipulating the Windows infrastructure.

Additionally, you should enable Potentially Unwanted Application protection for your Windows Defender scans: Right-click on the Start button and select Windows PowerShell (Admin), and then copy, paste, and enter this command:

Set-MpPreference -PUAProtection 1

https://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning-windows_10/windows-defender-not-detecting-known-adware/9cfe114b-8d1b-42a2-8268-34dc3acf9390 

A manual Full Scan can potentially find any malware that your AV app can possibly detect (with signatures) – but since real-time protection (on-access) is always automatically scanning the files involved in file system read/write operations; on-access scanning will generally find any active malware. And consequently, manual (or scheduled) scans will normally only find archived malware, or maybe some leftover malware fragments that were missed by real-time protection. The main reason for running manual scans is that they take the time to unpack container files and scan the contents, while real-time protection doesn’t scan the contents of archived files. So manual or scheduled scans with the installed AV app really have a very low priority, and generally won’t find any active malware.

But since no single AV app covers the entire spectrum of online threats, it’s entirely possible that your primary AV app might have missed some active malware – and that should always be your main concern. So the priority should always be on running some manual scans with third-party malware-removal apps, since these often include definitions that aren’t included in your installed AV app – and these third-party apps will consequently have the potential for detecting active malware that’s running on the system just because you primary AV app wasn’t able to detect it:

Kaspersky Virus Removal Tool:

http://support.kaspersky.com/viruses/kvrt2015

Emsisoft Emergency Kit:

http://www.emsisoft.com/en/software/eek/

Malwarebytes Anti-Malware (free version only):

https://www.malwarebytes.org/antimalware/

Eset Online Scanner:

http://www.eset.com/us/online-scanner/

Some other trusted third-party malware-removal tools are listed here:

https://answers.microsoft.com/en-us/protect/wiki/protect_other-protect_scanning/list-of-malware-removal-tools/d824b9af-ebd8-4c47-94e2-8ee6c544c100

GreginMich

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Anonymous
    2017-12-11T07:32:37+00:00

    I had the same issue, same results.  I was able to find/remove several Trojans using Windows Defender that comes with Windows doing a full scan.

    Was this answer helpful?

    0 comments No comments