Found this on my Windows 10 desktop, currently offline, running Defender full scan. It doesn’t show up on quick scan. I hit the take action button ang is says “Defender couldn’t completely resolve potential threats”. Ran the Defender offline scan. It gets to 93% and just reboots without taking any action. Malware Bytes doesn’t find the problem. An article from Microsoft earlier this year says Defender should remove this. Perhaps it has evolved to block removal. Any suggestions?
![]() |
Patch reliability is unclear, but widespread attacks make patching prudent. Go ahead and patch, but watch out for potential problems. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Problem with Trojan – JS/Obfuse.RVCC!MTB
Home » Forums » Cyber Security Information and Advisories » Cyber Security for Home Users » Problem with Trojan – JS/Obfuse.RVCC!MTB
- This topic has 14 replies, 6 voices, and was last updated 8 months, 1 week ago.
AuthorTopicGroundhog45
AskWoody PlusAugust 17, 2024 at 12:02 pm #2697237Viewing 10 reply threadsAuthorReplies-
Geo
AskWoody PlusAugust 17, 2024 at 12:52 pm #2697239Scan couldn’t complete. Could be this.
If scans are taking too long or appear to be progressing very slowly, consider the following solutions:
<b class=”ocpLegacyBold”>Make sure you have enough available disk space</b>
Microsoft Defender Antivirus requires disk space to remove and quarantine malware files. It might be prevented from completely removing a threat if there isn’t enough available space on your PC, particularly on your system drive (usually drive C). See the following to help free up space:
After you’ve freed up some space, update and then run a scan again.
Full scans can take a long time if you have a large disk with lots of files. Large files, especially archives such as ZIP files, take longer to scan.
<b class=”ocpLegacyBold”>Run scans while your PC is idle by closing all other programs</b>
Scanning takes system resources like processor and memory. If you have other programs running they may be creating a bit of a traffic jam that can slow down the malware scan, even if you’re not actively using them. Try closing any unnecessary apps while you run the scan.
-
Alex5723
AskWoody Plus -
Geo
AskWoody Plus -
Groundhog45
AskWoody PlusAugust 17, 2024 at 1:36 pm #2697247 -
Magnus
GuestAugust 17, 2024 at 1:40 pm #2697246You have doubtless done a Google search which brings up all manner of convoluted ‘solutions’ – particularly on the Malwarebytes and Malwaretips websites. The Malwaretips ‘solution’ in particular strikes me as being just a string of sponsored links.
I would start by checking the list of installed Apps (Start > Settings > Apps) and uninstalling any recently-installed and suspiciously-named App that you don’t recognise.
Second, download and run the easy-to-use Microsoft Safety Scanner:
https://learn.microsoft.com/en-gb/defender-endpoint/safety-scanner-download?view=o365-worldwide
2 users thanked author for this post.
-
Geo
AskWoody Plus -
Groundhog45
AskWoody PlusAugust 18, 2024 at 5:32 pm #2697557Well, I ran the Safety Scanner. After about 4 hours and 6.5 million files scanned, it said I had 55 infected files. But when it completed and was supposed to show me a list of the problem files, it said “no viruses, spyware, and other potentially unwanted software were detected”. I don’t think I’ve ever run into a problem like this.
-
Bob99
AskWoody MVPAugust 18, 2024 at 5:40 pm #2697558If you haven’t seen it already, the log for the Safety Scanner should be located at C:\Windows\debug\ and the file should be called “msert.log” and is viewable with Notepad or your choice of text file viewer.
I recall the same sort of thing happening to me quite some time ago…it said I had infections during the scan, but at the end it said my machine was clean. That was back in 2021, though.
By the way, the log for the Defender Offline scanner is located at
C:\Windows\Microsoft Antimalware\Support\msssWrapper.log
That might shed some light on why the offline scanner couldn’t complete its scan, as you mentioned in your original post. The log file can be opened with any text file viewer.
One more question: Exactly which file was infected with this alleged piece of crapware, or, Where did it say the infected file was located?
2 users thanked author for this post.
-
dgc-art
AskWoody PlusAugust 19, 2024 at 5:24 am #2697632When the Safety Scanner runs, it marks files it thinks may be infected then those files are compared to the malware database. If they are found to not contain malware then the scanner will indicate no problems were found. It is only if it finds malware in those files will it report at the end of the process and of any removal.
1 user thanked author for this post.
-
Groundhog45
AskWoody PlusMagnus
GuestAugust 19, 2024 at 7:05 am #2697611Do you remember how and when this infection started? Opening a particular email? Visiting a particular website?
If so, ensure the email has been permanently deleted, putting it in your Junk box first, so that the sender’s address is blocked. Fully empty your web browser’s cache. Check if any suspicious websites have been added to your browser’s Bookmarks/Favourites and, if so, delete them.
Restart your device and perform another scan with a fresh copy of MS Safety Scanner.
If this scenario doesn’t apply, then I would agree with Alex that restoring from an image backup is the next step – or even reinstalling Windows. Trojans are fiendishly hard to fully remove but cannot be ignored.
Groundhog45
AskWoody PlusAugust 19, 2024 at 5:22 pm #2697831Well, I looked at the logs for the MS Safety Scanner and the Defender offline scan. Both negative. Then I downloaded the latest version of the Windows Malicious Software Removal Tool so that I could run a full scan. Also negative. Defender full scan still shows that Trojan. I’m thinking that it was found and addressed but some traces are still found on the system that trigger the positive from Defender. I’ll probably restore my last backup to a different disk and see what it shows. It’s a couple of weeks old.
scan
1 user thanked author for this post.
-
Bob99
AskWoody MVPAugust 19, 2024 at 5:57 pm #2697839Open up Defender to the “Virus & threat protection” area and look below the “Quick Scan” button. There should be a clickable link in blue color that says “Protection history”. Click that and see if a file name or location is mentioned along with the infection’s name. If it just shows the name of the infection, oh well, at least you tried to find the location of the infection.
The very few times I’ve had “positives” has been for actions that a program was taking on my machine that Defender didn’t like (including a “positive” for chkdsk doing what I’d called on it to to). Each time, it mentioned the name of the “infection” or action, and the location it was in. This is why I was hoping it might do the same for you.
By the way, the MSRT, or Malicious Software Removal Tool only scans for a certain set of malware, not the whole gamut that Defender and the Safety Scanner look for.
1 user thanked author for this post.
Groundhog45
AskWoody PlusViewing 10 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Notice on termination of services of LG Mobile Phone Software Updates
by
Alex5723
10 hours, 15 minutes ago -
Update your Apple Devices Wormable Zero-Click Remote Code Execution in AirPlay..
by
Alex5723
6 hours, 16 minutes ago -
Amazon denies it had plans to be clear about consumer tariff costs
by
Alex5723
12 hours, 41 minutes ago -
Return of the brain dead FF sidebar
by
EricB
3 hours, 18 minutes ago -
windows settings managed by your organization
by
WSDavidO61
7 hours, 23 minutes ago -
Securing Laptop for Trustee Administrattor
by
PeachesP
7 hours, 35 minutes ago -
The local account tax
by
Susan Bradley
3 hours, 26 minutes ago -
Recall is back with KB5055627(OS Build 26100.3915) Preview
by
Alex5723
19 hours, 17 minutes ago -
Digital TV Antenna Recommendation
by
Win7and10
11 hours, 49 minutes ago -
Server 2019 Domain Controllers broken by updates
by
MP Support
1 day, 7 hours ago -
Google won’t remove 3rd party cookies in Chrome as promised
by
Alex5723
1 day, 8 hours ago -
Microsoft Manager Says macOS Is Better Than Windows 11
by
Alex5723
1 day, 12 hours ago -
Outlook (NEW) Getting really Pushy
by
RetiredGeek
14 hours, 26 minutes ago -
Steps to take before updating to 24H2
by
Susan Bradley
5 hours, 16 minutes ago -
Which Web browser is the most secure for 2025?
by
B. Livingston
18 hours, 53 minutes ago -
Replacing Skype
by
Peter Deegan
7 hours, 26 minutes ago -
FileOptimizer — Over 90 tools working together to squish your files
by
Deanna McElveen
1 day, 5 hours ago -
Excel Macro — ask for filename to be saved
by
nhsj
3 hours, 22 minutes ago -
Trying to backup Win 10 computer to iCloud
by
SheltieMom
7 hours, 12 minutes ago -
Windows 11 Insider Preview build 26200.5570 released to DEV
by
joep517
3 days, 11 hours ago -
Windows 11 Insider Preview build 26120.3941 (24H2) released to BETA
by
joep517
3 days, 13 hours ago -
Windows 11 Insider Preview Build 22635.5305 (23H2) released to BETA
by
joep517
3 days, 13 hours ago -
No April cumulative update for Win 11 23H2?
by
Peobody
2 days, 1 hour ago -
AugLoop.All (TEST Augmentation Loop MSIT)
by
LarryK
3 days, 14 hours ago -
Boot Sequence for Dell Optiplex 7070 Tower
by
Serge Carniol
4 days, 5 hours ago -
OTT Upgrade Windows 11 to 24H2 on Unsupported Hardware
by
bbearren
4 days, 8 hours ago -
Inetpub can be tricked
by
Susan Bradley
2 days, 16 hours ago -
How merge Outlook 2016 .pst file w/into newly created Outlook 2024 install .pst?
by
Tex265
3 days, 2 hours ago -
FBI 2024 Internet Crime Report
by
Alex5723
4 days, 12 hours ago -
Perplexity CEO says its browser will track everything users do online
by
Alex5723
1 day, 21 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.