Safety Scanner found 12 infected files but scan results said no problems detected

Catwoman 31 Reputation points
2021-06-03T16:12:29.03+00:00

I ran a Microsoft Security Scan and during the scan I could see that it had found 12 infected files. When the scan completed, it said that there were no viruses, spyware, or other potentially unwanted software detected. I have attached screen shots.102172-img-5208.jpg102126-img-5205.jpg

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,771 questions
{count} votes

11 answers

Sort by: Most helpful
  1. Yuhan Deng 3,761 Reputation points Microsoft Vendor
    2021-06-04T02:17:50.39+00:00

    Hi,

    To truly answer your question, you need to understand how the Microsoft security apps actually operate, since that's part of why this sort of situation can be confusing to those who don't.

    The "Files Infected" count displayed on the Microsoft Safety Scanner, scan in progress screen or any of their other security products for that matter, is actually just a preliminary status indication that there are items which may contain malware. In many cases these specific items have been found in the past to be related to malware, but they are all really just small fragments that have matched signatures, but aren't yet truly confirmed as the specific malware that might include them.

    Near the end of the scanning process, say 95% complete, the Microsoft scanners all perform a MAPS (Microsoft Active Protection Service) request via internet to the the Microsoft cloud servers in order to upload their initial findings and request confirmation that these findings are either truly malware or instead possible false positive detections or incomplete fragments of inactive malware.

    So what actually happened is that the scanner found possible malware fragments, communicated with the MAPS servers and confirmed there weren't any active malware that it can identify running and completed its operation by reporting these final results as well as uploading its reporting to MAPS as a record.

    Back to your case, according to the screenshots there's nothing truly wrong with what the Safety Scanner found.

    Thanks for your time.
    Best regards,
    Danny

    -----------------------------

    If the Answer is helpful, please click "Accept Answer" and upvote it.

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    13 people found this answer helpful.

  2. John Clegg 51 Reputation points
    2022-01-12T03:21:34.677+00:00

    Danny, your answer is just silly.

    What is wrong with Catwoman-3559's screenshots are that the first one says "Infected files: 12" and then the second one says "The scan completed successfully and no viruses, spyware, and other potentially unwanted software were detected."

    These two pieces of information directly contradict each other and simply don't make sense.

    MS could easily correct this confusion by changing the verbiage in the initial screenshot to “Possibly" Infected files: 12” or "Potentially" Infected files: 12" AND something like "Please see final "Scan results."

    -John

    10 people found this answer helpful.

  3. Jon M 51 Reputation points
    2022-02-03T14:42:55.13+00:00

    I agree with @John Clegg here about the contradictory messaging. The scan progress screen should show "Suspicious files: 12" -- not "Files Infected: 12"

    Additionally, based on the description @Yuhan Deng gave of what the tool actually does, the description at the top of the scan progress screen should be modified to say something like this: "After this operation completes, the tool will send any suspicious files to Microsoft to determine if they are viruses, spyware, or other potentially unwanted software and report the results."

    That would reassure users that the suspicious files will be further evaluated to determine if they are actually infected, so the final result of no infections will not be so contradictory that it leads to posts being created on Microsoft forums.

    And since I'm already in here giving unsolicited advice about how to improve an already useful tool, it would be helpful if there was some indication of what it is doing when it starts the progress bar over again. Even if I start it on a scan of just the C drive, it seems to scan it multiple times. I assume it's using a different heuristic each time or something, but a better indication of how many heuristics or how many scans it needs would be nice. That would help me to estimate how much longer it will take to complete. The full scan takes all day on my computer with tons of files, so that extra indication would be very informative.

    10 people found this answer helpful.

  4. Nicholas Q 20 Reputation points
    2023-04-12T17:23:07.0866667+00:00

    I also agree with the need for new wording on this tool. I was just doing a web search to see what sort of terrible virus was manipulating my AV software. I've been using 6 different tools for the last two days and these "infected" files kept me concerned.

    4 people found this answer helpful.
    0 comments No comments

  5. Erik R. Grenee 15 Reputation points
    2023-05-16T20:17:10.1733333+00:00

    I am encountering the same issue: Microsoft Safety Scanner 1.389.705.0 indicates Files Infected. The present count is at '2'. When I initially ran this scan the count was '14' (if I recall correctly). There where no recommended further steps recommended. 3rd party scanners don't indicate any infection but this is a Microsoft Operating System so I defer to Microsoft KB. Is my OS infected as Microsoft Safety Scanner 1.389.705.0 suggest or is Danny on point and some harmless code fragment has triggered these notifications? Kind of concerned since I had to return this device to the factory days after it's arrival due to an unauthorized web access and lateral movement.

    3 people found this answer helpful.
    0 comments No comments