Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Short answer: A Malwarebytes Trojan alert does not prove that your computer is still infected, but a later clean scan does not prove that the alert was a false positive. Keep the item quarantined, record the detection details, run layered scans, investigate how the file got there, and protect your accounts if the file may have executed.

If the alert returns after reboot, security tools were disabled, a rootkit or driver was involved, or sensitive credentials may have been exposed, treat the incident as serious. Run an offline scan and consider a clean Windows reinstall.

What a Trojan detection actually tells you

“Trojan” is a broad detection category, not a complete diagnosis. Malwarebytes may identify a file, running memory object, registry startup entry, malicious website, potentially unwanted program, or suspicious behavior. A label such as Trojan.Generic, Trojan.MalPack, or Heuristics.Generic does not identify the malware family by itself.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Separate these four questions:

  • What was detected? The detection name, path, hash, behavior, and object type provide the evidence.
  • Was it isolated? Quarantine prevents the detected item from operating normally. Malwarebytes says quarantined items cannot harm the device while they remain quarantined.
  • Are other threats present? A clean scan means that particular scan found nothing in the locations and categories it examined.
  • Was anything stolen or changed? Scanning cannot reliably establish whether passwords, cookies, documents, or other data were copied before removal.

Therefore, “Malwarebytes found a Trojan” and “the computer is clean now” are not contradictory statements. The first may describe a successfully blocked threat; the second requires broader evidence.

#1 Best Overall
Sandisk 2TB Extreme Portable SSD, Up to 1050MB/s, USB-C, USB 3.2 Gen 2, IP65 Water and Dust Resistance, Updated Firmware, External Solid State Drive, SDSSDE61-2T00-G25
  • Get NVMe solid state performance with up to 1050MB/s read and 1000MB/s write speeds in a portable, high-capacity drive(1) (Based on internal testing; performance may be lower depending on host device & other factors. 1MB=1,000,000 bytes.)
  • Up to 3-meter drop protection and IP65 water and dust resistance mean this tough drive can take a beating(3) (Previously rated for 2-meter drop protection and IP55 rating. Now qualified for the higher, stated specs.)
  • Use the handy carabiner loop to secure it to your belt loop or backpack for extra peace of mind.
  • Help keep private content private with the included password protection featuring 256‐bit AES hardware encryption.(3)
  • Easily manage files and automatically free up space with the SanDisk Memory Zone app.(5). Non-Operating Temperature -20°C to 85°C

See Malwarebytes’ guidance on signs of infection and its explanation of quarantined items.

Step 1: Preserve the detection details

Before deleting anything, open Malwarebytes and record:

  • Detection name
  • Full path and filename
  • File extension
  • Detection type, such as file, memory object, startup item, web block, PUP/PUM, or rootkit
  • Date and time
  • Scan type
  • Whether Malwarebytes quarantined, ignored, or merely blocked it
  • Whether a restart was requested

Open Detection History and inspect the relevant report. Malwarebytes documents that scan reports include the scan type, detection details, and date/time, and that Windows reports can be copied or downloaded as text files. Save the report if the computer belongs to an employer, the incident may involve fraud, or you may need vendor or professional support.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Do not restore or execute the file while investigating it.

Step 2: Confirm what happened to the file

Malwarebytes actions have different consequences:

Action Meaning
Quarantine The item is moved to Malwarebytes’ isolated area and should not execute normally.
Ignore once The item remains on the computer and may be detected again.
Allow list or Ignore always Future detections may be suppressed. This can hide a real threat.
Restore The item is returned to the computer. Use this only after independent verification.
Delete from quarantine The quarantined copy is removed, but this does not prove that related files or persistence mechanisms are gone.

Keep the item quarantined while you investigate. Do not add a broad folder exclusion simply to make the alert disappear.

Rank #2
Sandisk 1TB Portable SSD, Up to 800MB/s Read Speeds, Black (Old Model)
  • Solid state performance with up to 800MB/s read speeds in a portable drive. (Based on internal testing; performance may be lower depending on host device, interface, usage conditions and other factors. 1MB=1,000,000 bytes.)
  • Back up your content and memories on a storage solution that fits seamlessly into your mobile lifestyle.
  • Take it with you on your adventures—up to two-meter drop protection means this durable drive can take a beating. (Based on internal testing.)
  • Secure it to your belt loop or backpack for extra peace of mind thanks to the tough rubber hook.
  • From Sandisk, a brand professional photographers trust to take on assignments.

Step 3: Test whether it could be a false positive

A false-positive investigation should use evidence, not just the filename or the fact that a later scan is clean.

  1. Assess the path. A file in a known vendor installation directory is less suspicious than a randomly named executable in %AppData%, %Temp%, %Public%, or a user-profile startup folder. Location is a clue, not a verdict.
  2. Check the publisher and signature. In Windows File Explorer, open the file’s properties and inspect the Digital Signatures tab when available. A valid signature is useful evidence but is not an automatic safety guarantee.
  3. Compare the hash. If the software vendor publishes a checksum, compare it with the detected file. A matching hash supports authenticity; a mismatch is a reason not to restore it.
  4. Consider the source. Cracks, key generators, unofficial installers, unexpected email attachments, and browser extensions deserve a much higher level of suspicion than software downloaded from the vendor’s official site.
  5. Use multi-engine analysis carefully. A hash or file can be checked with a reputable service such as VirusTotal. “Zero detections” is supporting evidence, not proof of safety. Do not upload confidential documents, proprietary software, credentials, or personal data.
  6. Ask Malwarebytes to review it. Paid subscribers can contact Malwarebytes Support about suspected false positives. Other users can use Malwarebytes’ false-positive reporting process.

If the file belongs to a legitimate application, the safest recovery is often to delete the quarantined copy and reinstall that application from its official source rather than restoring the flagged executable.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Step 4: Run layered scans

Use a sensible sequence instead of installing several competing real-time antivirus products.

  1. Update Malwarebytes. Restart if it requests a restart.
  2. Run a Threat Scan. Malwarebytes describes this as its recommended general scan for common threat locations.
  3. Quarantine confirmed detections. Restart if prompted.
  4. Run a deeper check when justified. Use a Custom Scan or Deep Scan if the original item was an executable, startup object, suspicious process, or recurring detection. Custom Scan can provide control over drives, folders, memory, startup items, archives, and, where supported, rootkits.
  5. Enable rootkit scanning where available. It can increase scan time and is not available in the documented Custom Scan workflow on ARM-based devices.
  6. Run Microsoft Defender. A second, independent scanner provides additional evidence. Use its normal scan for routine checking.
  7. Repeat after reboot. A threat that returns after restarting requires escalation.

Malwarebytes says manual scanning is available in free and paid versions, while scheduling is a paid feature. You do not need a subscription merely to perform a manual cleanup scan. Its documented scan details are available in the scan-type guide and scan-settings guide.

Optional Microsoft Defender PowerShell checks

These commands require an appropriate Windows edition, Defender configuration, and often administrator privileges. Run PowerShell as an administrator and save your work first, especially before requesting an offline scan.

Rank #3
SSK Portable SSD 500GB External Solid State Hard Drive USB C Up to 1050MB/s
  • Capacity Display Variance: 500GB external ssd often appears as around 465GB on Windows. MacOS can show full 500 GB capacity. This is binary calculation difference and doesn’t affect SSD hard drive actual physical storage
  • 1050 MB/s Speed: Instantly access to your files with blazing-fast 10Gbps external SSD read up to 1050MB/s and write up to 1000MB/s. LED Light indicates USB SSD instant activity
  • Data Security: Solid state drives S.M.A.R.T. health diagnostics​ and adaptive TRIM optimizing data block management ensures consistent write speeds and extends the longevity of the portable SSD
  • USB-C & USB-A Cable: Both cables featuring rapid USB 3.2 Gen2, this USB SSD effortlessly bridges devices, enabling seamless cross-platform file transfers and backup between computers, smartphones, tablets and iPhone
  • Always Fast: No slowdowns for large file transfers. With SLC caching (25% of current available capacity allocated as high-speed cache), this external SSD delivers steady 10Gbps for transfers within the cache capacity
Get-MpThreatDetection
Get-MpComputerStatus
Start-MpScan -ScanType FullScan
Start-MpWDOScan

Get-MpThreatDetection shows Defender’s detection history where the Defender PowerShell module is available. Get-MpComputerStatus displays Defender status information. Start-MpScan -ScanType FullScan starts a full scan, while Start-MpWDOScan requests a Microsoft Defender Offline scan and normally reboots the computer. Windows commands and labels vary by Windows release, policy, and build.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

When to use an offline scan

An offline scan starts outside the normal Windows environment. That reduces the opportunity for active malware to hide from or interfere with the scan.

Use one when:

  • The detection involves a rootkit, boot sector, driver, or system process.
  • Security software has been disabled or repeatedly re-enabled.
  • The computer redirects browsers, creates unexplained administrator accounts, or reinfects itself after reboot.
  • Malwarebytes says removal requires a restart but the same detection returns.
  • You cannot trust scans performed while Windows is running.

Exact Windows Security menu labels differ by Windows version, language, policy, and Defender update. Follow the current options shown in your installation rather than relying on an old menu path.

Step 5: Check for persistence and continuing symptoms

A clean Malwarebytes report is reassuring, but review the surrounding system if the detection was serious or the computer still behaves abnormally. Look for:

  • Unknown startup applications
  • Unexplained scheduled tasks or services
  • New administrator accounts
  • Unknown browser extensions
  • Changed proxy or DNS settings
  • Unexpected certificates installed in Windows or the browser
  • Disabled security notifications or tampered security settings
  • Repeated detections after reboot
  • Unexpected outbound traffic or account-login alerts

Do not assume that System Restore is complete remediation. A scheduled task, service, browser extension, altered setting, or second-stage payload may survive removal of the main file.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Sale
Seagate 2TB Portable Hard Drive | USB 3.0 (STGX2000400)
  • Easily store and access 2TB to content on the go with the Seagate Portable Drive, a USB external hard drive
  • Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
  • To get set up, connect the portable hard drive to a computer for automatic recognition no software required
  • This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
  • The available storage capacity may vary.

What “clean enough to continue” looks like

Evidence Interpretation
The item is quarantined and remains there The detected file is no longer normally executable.
Threat Scan is clean No threat was found in the scan’s examined locations and categories.
Deeper or Custom Scan is clean when warranted Confidence increases, especially for startup, archive, memory, or rootkit concerns.
Microsoft Defender scan is clean An independent product found no known threat in its scan.
No recurring alert or suspicious behavior after reboot There is no obvious sign of active persistence.
Accounts and browser settings are normal No obvious evidence of continuing account or configuration abuse.

This is strong practical evidence, not a guarantee that the computer is mathematically or permanently free of malware.

If the file may have run

Removal does not reverse credential theft or data exfiltration. If you opened the file, granted it administrator access, or cannot determine whether it ran, act as though exposure is possible.

  1. Disconnect the computer from the internet if active compromise is suspected.
  2. Do not use the potentially compromised computer for banking, password changes, or sensitive communications.
  3. From a known-clean device, change important passwords, starting with email, banking, password managers, cloud storage, and social accounts.
  4. Revoke active sessions where each service supports it.
  5. Enable multifactor authentication.
  6. Review recent sign-ins, recovery addresses, email-forwarding rules, and password-reset messages.
  7. Contact financial institutions if payment or financial information may have been exposed.
  8. Check other computers, shared folders, USB drives, and cloud-sync locations.

If the computer belongs to an employer or contains regulated or sensitive business information, preserve logs and contact IT or the organization’s security team before wiping it.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

When reinstalling Windows is the right answer

A clean reinstall is not necessary for every isolated detection. It is the strongest practical option when trust in the running operating system has been lost.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Prefer an offline scan and seriously consider a clean reinstall when:

Best Value
Sale
Samsung T7 Portable SSD 1TB Titan Gray, USB 3.2 Gen 2, Up to 1,050MB/s
  • MADE FOR THE MAKERS: Create; Explore; Store; The T7 Portable SSD delivers fast speeds and durable features to back up any endeavor; Build your video editing empire, file your photographs or back up your blogs all in an instant
  • SHARE IDEAS IN A FLASH: Don’t waste a second waiting and spend more time doing; The T7 is embedded with PCIe NVMe technology that brings fast read and write speeds up to 1,050/1,000 MB/s¹, making it almost twice as fast as the T5
  • ALWAYS MAKE THE SAVE: Compact design with massive capacity; With capacities up to 4TB, save exactly what you need to your drive – from large working files to game data and everything in between
  • ADAPTS TO EVERY NEED: Whether using a PC or mobile phone, count on the T7 for extensive compatibility²; It’s a true team player when it comes to heavy-duty application usage or file-saving
  • HI RESOLUTION VIDEO RECORDING: Record Ultra High Resolution (4K 60fs) videos directly onto the T7 Portable SSD with your favorite camera or mobile devices; Supports iPhone 15 Pro Res 4K at 60fps video and more³
  • A rootkit or boot-level compromise is suspected.
  • The malware had administrator privileges.
  • The same detection returns after reboot or repeated cleaning.
  • Security tools were disabled or tampered with.
  • There is unexplained account, network, or administrator activity.
  • The machine contains high-value credentials or sensitive business data.
  • You need the highest reasonable confidence rather than “probably clean.”

Prepare safely

  • Back up documents, photos, and other non-executable personal data.
  • Do not blindly restore programs, scripts, macros, cracks, browser extensions, or unknown executables.
  • Scan backups from a separate clean system.
  • Use Windows installation media obtained from Microsoft.
  • Record software licenses, recovery keys, and important configuration details.
  • Change passwords from a separate clean device, preferably before or during the reinstall.

A reinstall removes the operating system and applications; it does not undo data theft that already occurred, recover encrypted or deleted files, or automatically secure online accounts.

Troubleshooting common outcomes

Malwarebytes finds the same item again

Do not keep restoring or ignoring it. Record the new report, run a deeper scan and an offline scan, and investigate persistence. Repeated detection after reboot is a strong reason to reinstall or seek professional help.

The detection is inside a legitimate program folder

Do not assume either a false positive or a clean file. Check the signature, publisher, hash, download source, and whether the application recently updated. Reinstall from the official vendor rather than restoring the flagged file.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The scan stops or cannot remove the file

Restart if prompted, update the security tools, and run the scan again. If removal still fails, use an offline scan. Avoid manually deleting system files unless you have verified what they are.

Windows Security is disabled

That may be a policy setting, another antivirus product, or malware tampering. If you did not intentionally change it, treat the condition as suspicious and escalate to offline scanning or professional support.

The browser is still redirecting

Check extensions, proxy and DNS settings, certificates, and installed applications. Adware or potentially unwanted programs may be involved. Malwarebytes AdwCleaner is designed for adware, PUPs, browser hijackers, and unwanted preinstalled software, but it is not a universal replacement for antivirus or incident response. Follow its documented workflow: Scan Now, review results, choose Quarantine, restart if prompted, and review the log. Use Basic Repair only when directed by Malwarebytes Support.

See the AdwCleaner instructions.

An application needs the quarantined file

Do not restore it just because the program stops working. Obtain a fresh installer from the official vendor, verify its publisher where possible, and reinstall it. If the application is unofficial, modified, cracked, or bundled with a key generator, remove it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Final decision checklist

If this is true Do this
One suspicious download was blocked and quarantined, with no symptoms Keep it quarantined, update Malwarebytes, run a Threat Scan and a Defender scan.
A legitimate application was detected in its normal folder Verify its signature and hash, then reinstall from the official source if needed.
The item was in a temporary, profile, startup, or randomly named location Run deeper scans and inspect persistence.
The detection returns after reboot Run an offline scan and prepare for a clean reinstall.
A rootkit, boot threat, driver, or security-tool tampering is involved Use an offline scan; reinstall if trust cannot be restored.
The file ran with administrator rights Protect accounts from a clean device and consider a reinstall.
The system is business-critical or evidence may matter Contact IT or a qualified incident-response professional before wiping it.

Do not run multiple real-time antivirus products simultaneously, disable protection to launch an unknown installer, restore old executable files blindly, or reconnect unscanned USB drives and backups immediately after cleanup.

Quick Recap

Bestseller No. 2
Sandisk 1TB Portable SSD, Up to 800MB/s Read Speeds, Black (Old Model)
Sandisk 1TB Portable SSD, Up to 800MB/s Read Speeds, Black (Old Model)
From Sandisk, a brand professional photographers trust to take on assignments.
$165.70
SaleBestseller No. 4
Seagate 2TB Portable Hard Drive | USB 3.0 (STGX2000400)
Seagate 2TB Portable Hard Drive | USB 3.0 (STGX2000400)
This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable; The available storage capacity may vary.
$129.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.