📎 AI Summary:
The thread discusses a user's issue with Windows Defender detecting a severe Trojan ("HTML: Phiz!pz") but failing to complete remediation despite multiple scans and malware removal tools. The user suspects a false positive due to the file paths and persistent detection, and notes that the Trojan may be interfering with system backups. A responder suggests that the detection might be a false positive and that cleanup could fail if the infected files are in use, implying the need for further troubleshooting or advanced removal steps.

Joe27

Honorable Member
Joined
Feb 8, 2018
Messages
12
Thread Author #1
Remediation Incomplete.

I got a notification from Windows Defender that a Trojan had been detected on my laptop, but “Remediation was Incomplete” and the threat remained “Severe”. How do I complete remediation please?

So far I have tried: 1. A Windows Defender Quick Scan – nothing detected; 2. A WD Full Scan – nothing detected; 3. A WD Offline Scan – nothing detected, and 4. a Malwarebytes scan – nothing detected. So I scanned with Microsoft Security Scanner (MSERT) which froze at the three quarter mark having identified 75 infections. I then freed up space by deleting Firefox cache files and scanned again with MSERT on two occasions several days apart, with the same result -the scan froze each time at the three quarter mark and wouldn’t complete.

NOTE : I am running Windows 10, 64 bit. The malware is “ Trojan HTML: Phiz!pz”. The MERST scan stopped twice on the same file (C/Programme files (x86)HP/HP RegistrationService/HPGenOOBE,exe) and once on (E:preload\install31.swm). Defender said the affected items are Firefox\Profiles\f590f2zl.default\czche2\entries. Windows routine Back-Up is obviously affected too since on the last two occasions it has tried to run it has been stopped by the Trojan.

NOTE 2: There is plenty of space on the C: G: and D: drives and 1.41 GB remaining on the E: drive. Around 30 million files had been scanned by the time MERST froze and around 80 infections had supposedly been detected

Thanks for any help.
 

Solution
The 'Trojan HTML:....' is just a generic tag/category assigned to the suspected malware. Based on the file path this is likely a false positive and you can probably just mark it as such.

Clean up / containment can fail for varying reasons, such as if the file is in use.

Neemobeer

Windows Forum Team
Staff member
Joined
Jul 4, 2015
Messages
8,995
The 'Trojan HTML:....' is just a generic tag/category assigned to the suspected malware. Based on the file path this is likely a false positive and you can probably just mark it as such.

Clean up / containment can fail for varying reasons, such as if the file is in use.
 

Solution