Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteSome links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Short answer: the BleepingComputer thread titled “New Malware impossible to remove” does not prove that a new malware strain, rootkit, or drive-wide infection existed. It records a user’s reports of conflicting Microsoft Safety Scanner results, disabled-looking Microsoft Defender protection, and suspected detections including VIRTOOL:Win32DefenderTamperingRestore and RemoteAdmin:Win32ConnectScreen. After reviewing Farbar Recovery Scan Tool logs and applying a computer-specific fix, a volunteer concluded on September 9, 2022 that the computer was clean.
That conclusion belongs to the responder and is not independent forensic certification. The useful lesson is broader: malware can appear to return because of incomplete scans, quarantine history, persistence, reinfection from removable media, legitimate remote-administration software, or security-configuration problems.
What happened in the original case?
The thread began on September 6, 2022, in BleepingComputer’s Virus, Trojan, Spyware, and Malware Removal Help forum. The poster believed a rootkit, Trojan, or virus was surviving repeated cleanup attempts, affecting internal and USB drives, and disabling Microsoft Defender.
The user reported that Microsoft Safety Scanner (MSERT) appeared to detect four files during scanning, but that its final report reportedly said nothing was found. The suspected names included VIRTOOL:Win32DefenderTamperingRestore and RemoteAdmin:Win32ConnectScreen. Malwarebytes was also reported not to have solved the issue.
#1 Best Overall
- ONGOING PROTECTION Download instantly & install protection for 3 PCs, Macs, iOS or Android devices in minutes!
- TOP-PERFORMING VPN Faster speeds, more server locations, and greater connection control to protect your privacy across all your devices, including Smart TVs.
- ADVANCED SCAM PROTECTION Help spot hidden scams online. With the built-in Genie AI assistant, you’ll never wonder if a message or email is suspicious again.
- REAL-TIME PROTECTION Advanced security protects against existing and emerging malware threats, including ransomware and viruses, and it won’t slow down your device performance.
- DARK WEB MONITORING Identity thieves can buy or sell your information on websites and forums. We search the dark web and notify you should your information be found.
A BleepingComputer malware-response volunteer used Farbar Recovery Scan Tool (FRST) to inspect the installation. The case-specific fix addressed a suspicious WinSetupMon service, firewall rules, Defender settings, system-component checks, and temporary files. The responder later stated that the computer was “absolutely clean of malware.” Read the original support thread for the complete case record.
What the thread does not establish is that the incident involved a newly discovered malware family, a kernel rootkit, unauthorized remote access, data theft, or infection of every connected drive.
What the detection names do—and do not—mean
VIRTOOL:Win32DefenderTamperingRestore appears to describe a tool or behavior associated with changing or restoring Microsoft Defender settings. It is not, by itself, proof of a rootkit.
RemoteAdmin:Win32ConnectScreen appears to identify remote-administration software or behavior. Remote-control software can be legitimate, unwanted, or malicious depending on who installed it, how it is configured, and whether its access is authorized. The label alone does not prove that an attacker controlled the computer.
Before deleting anything, preserve the exact detection name, complete path, timestamp, security product, engine or definition version, and action taken. A filename or detection label without that context is weak evidence.
Rank #2
- DEVICE SECURITY - Award-winning McAfee antivirus, real-time threat protection, protects your data, phones, laptops, and tablets
- SCAM DETECTOR - We'll automatically identify risky texts, emails, and videos that attempt to steal your personal or financial information. You can even use our mobile app to check social messages and QR codes for scams on-demand, without missing a beat.
- SECURE VPN – Secure and private browsing, unlimited VPN, privacy on public Wi-Fi, protects your personal info, fast and reliable connections
- IDENTITY MONITORING – 24/7 monitoring and alerts, monitors the dark web, scans up to 60 types of personal and financial info
- SAFE BROWSING – Guides you away from risky links, blocks phishing and risky sites, protects your devices from malware
Why a detection can seem to disappear and return
Different scan stages may produce different results
An alert shown while a scanner is processing files is not the same as a confirmed item in quarantine. A scanner may identify a transient file, fail to access it, clean it before producing the final report, or stop before completing the scan. A final “nothing found” report may therefore refer to the machine’s state at the end of that scan rather than contradict every earlier message.
Check whether the scan completed, whether the alert was quarantined or removed, and whether the reported path still exists. Also determine whether the notification is current or merely being displayed from a historical log.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Persistence may remain after the visible file is removed
Deleting an executable does not necessarily remove a scheduled task, Windows service, startup entry, driver, browser extension, WMI subscription, firewall rule, or installer that can restore it. Conversely, an unfamiliar startup item is not automatically malicious; legitimate software often creates services and scheduled tasks.
Removable media can reintroduce software or symptoms
A USB drive can contain unwanted executables, shortcut files, hidden files, installers, or a legitimate tool that a security product flags. The original thread records the user’s report that internal and USB drives were affected, but it does not independently prove that every drive was infected.
Disconnect external drives while investigating. Scan each drive separately, avoid opening unknown executables, and do not reconnect backups until the computer and the backup’s contents have been checked.
Rank #3
- ONGOING PROTECTION Download instantly & install protection for 5 PCs, Macs, iOS or Android devices in minutes!
- TOP-PERFORMING VPN Faster speeds, more server locations, and greater connection control to protect your privacy across all your devices, including Smart TVs.
- ADVANCED SCAM PROTECTION Help spot hidden scams online. With the built-in Genie AI assistant, you’ll never wonder if a message or email is suspicious again.
- REAL-TIME PROTECTION Advanced security protects against existing and emerging malware threats, including ransomware and viruses, and it won’t slow down your device performance.
- DARK WEB MONITORING Identity thieves can buy or sell your information on websites and forums. We search the dark web and notify you should your information be found.
Defender may be disabled for several reasons
A disabled-looking Defender state can result from another antivirus product, organizational policy, Safe Mode, corrupted Windows components, user configuration, or actual tampering. It is concerning, but it is not conclusive proof of malware.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchErrors involving Defender in Safe Mode also need context: some security services are not designed to operate normally in that mode. Safe Mode errors alone do not demonstrate an attack.
A legitimate remote tool may be detected as a risk
Remote-administration programs can be used by businesses, support technicians, family members, or attackers. Verify who installed the software, whether its use is expected, which accounts can connect, and whether its access logs are understood. Do not remove it solely because its name sounds suspicious.
A safe way to investigate
- Stabilize the situation. Stop entering passwords, banking details, or other sensitive information on the device while compromise is plausible. Disconnect removable drives.
- Contain active threats. Disconnect the computer from the network immediately if there is evidence of remote control, ransomware, mass file encryption, credential theft, unusual outbound traffic, or an attacker-created administrator account. For a single unexplained alert with no active symptoms, temporary disconnection while collecting evidence is reasonable.
- Record the alert. Save the detection name, full path, date and time, scanner, engine or definition version, scan type, completion status, and remediation result. A screenshot or exported report is useful.
- Update supported software. Update Windows and the installed security product before running a new full scan. Avoid running several competing real-time antivirus products at the same time.
- Run a complete scan. Allow it to finish. If normal Windows scanning is interrupted, Defender remains disabled, or persistence is suspected, use an offline or boot-time scan supplied by a reputable security vendor.
- Repeat carefully. Reboot only when the security product requests it, then check whether the same detection returns. A repeat alert with the same path and action is more informative than a vague claim that “the virus came back.”
- Escalate when necessary. Preserve logs and use a reputable malware-removal forum or qualified technician for individualized analysis.
Remove usernames, email addresses, license keys, IP addresses, and personal file paths before posting logs publicly.
Do not copy another user’s FRST fix
FRST can expose persistence mechanisms that ordinary antivirus scans do not explain, but its fixes are constructed for a specific computer after an analyst reviews that computer’s logs. The responder in the original thread explicitly warned the user not to make changes, delete files, edit the registry, or run tools unless instructed.
Recommended Free Tools
Rank #4
- SPEED-OPTIMIZED, CROSS-PLATFORM PROTECTION: World-class antivirus security and cyber protection for Windows (Windows 7 with Service Pack 1, Windows 8, Windows 8.1, Windows 10, and Windows 11), Mac OS (Yosemite 10.10 or later), iOS (11.2 or later), and Android (5.0 or later). Organize and keep your digital life safe from hackers
- SAFE ONLINE BANKING: A unique, dedicated browser secures your online transactions; Our Total Security product also includes 200MB per day of our new and improved Bitdefender VPN
- ADVANCED THREAT DEFENSE: Real-Time Data Protection, Multi-Layer Malware and Ransomware Protection, Social Network Protection, Game/Movie/Work Modes, Microphone Monitor, Webcam Protection, Anti-Tracker, Phishing, Fraud, and Spam Protection, File Shredder, Parental Controls, and more
- ECO-FRIENDLY PACKAGING: Your product-specific code is printed on a card and shipped inside a protective cardboard sleeve. Simply open packaging and scratch off security ink on the card to reveal your activation code. No more bulky box or hard-to-recycle discs. PLEASE NOTE: Product packaging may vary from the images shown, however the product is the same.
Do not copy commands from that case, including the PowerShell Defender commands, service removal, firewall-rule deletion, or the DISM.exe /Online /Cleanup-Image /Restorehealth and SFC /ScanNow sequence, as a universal cleanup recipe. Used in the wrong environment, a custom fix can disable security, remove legitimate software, or make recovery harder.
When should you reinstall Windows?
Attempt cleanup when the detection is isolated, quarantine succeeds, security controls can be restored, there is no evidence of credential theft or attacker activity, and a qualified analyst can review the logs.
A clean reinstall is more defensible when a boot-level compromise is credibly suspected, Defender and other security controls remain disabled, an attacker account or remote-control activity is found, malware returns after verified cleanup, or the computer contains highly sensitive information.
Reinstalling Windows removes local persistence, but it does not secure online accounts, cloud-synchronized browser extensions, infected backups, or removable drives. Before restoring data, scan external media and reinstall applications from trustworthy sources. Do not automatically restore an old disk image if it may contain the suspected problem.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Protect accounts as well as the computer
A local malware scare can be confused with account compromise. From a known-clean device, change important passwords, avoid reusing them, enable multifactor authentication, and revoke active sessions or browser tokens where the service allows it. Contact financial institutions if banking credentials may have been exposed.
Best Value
- DEVICE SECURITY - Award-winning McAfee antivirus, real-time threat protection, protects your data, phones, laptops, and tablets
- SCAM DETECTOR - We'll automatically identify risky texts, emails, and videos that attempt to steal your personal or financial information. You can even use our mobile app to check social messages and QR codes for scams on-demand, without missing a beat.
- SECURE VPN – Secure and private browsing, unlimited VPN, privacy on public Wi-Fi, protects your personal info, fast and reliable connections
- IDENTITY MONITORING – 24/7 monitoring and alerts, monitors the dark web, scans up to 60 types of personal and financial info
- SAFE BROWSING – Guides you away from risky links, blocks phishing and risky sites, protects your devices from malware
Replacing a router or PC is not proof that malware survived in hardware. Similar symptoms on a replacement machine may come from an infected USB drive, restored backup, reinstalled application, synchronized browser extension, reused credentials, or the same false positive.
What this case teaches
- A user’s suspicion is not the same as confirmed malware analysis.
- A detection name does not prove a rootkit, data theft, or infection of every drive.
- A scan alert, quarantine entry, remediation failure, and final scan report are different kinds of evidence.
- Disabled Defender protection deserves investigation but has several possible causes.
- Running more cleaners is not always safer; conflicting tools can create confusing results.
- Account security and removable-media hygiene matter even after a computer is cleaned.
- Custom FRST fixes must never be copied from another case.
The 2022 BleepingComputer thread is best understood as a historical support case about diagnostic uncertainty and individualized cleanup—not as evidence of a new malware outbreak.
Frequently Asked Questions
Can malware spread to USB drives?
It can place malicious or unwanted files on removable media, but a report that a USB drive triggered an alert does not prove that every file or drive was infected. Disconnect and scan removable media separately.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Does disabled Microsoft Defender prove infection?
No. Another antivirus product, policy, Safe Mode, corruption, user settings, or malware can produce that state. It is a warning sign that needs context.
Is remote-administration software always malicious?
No. It may be legitimate support software or an unauthorized tool. Verify its installer, owner, accounts, purpose, and access history.
Is a clean scan proof that a computer is safe?
No single scan proves that. Confidence depends on a completed scan, current definitions, consistent results, restored security controls, and—when needed—expert log analysis.
When should passwords be changed?
Change important passwords from a known-clean device as soon as credential theft is plausible, then enable multifactor authentication and revoke active sessions.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

