Solved Windows defender continually finds and deletes Trojan:Win64/Lazy.PGLI!MTB on daily startup.

Status
Not open for further replies.
These instructions from thewindowsclub are not accurate for windows10 defender. I have no tab to scan history for removal of files.
 
RegBak by Acelogix Software
  • Download RegBak by Acelogix Software and save it to your Desktop.
  • Note: If you are warned of a suspicious site you can ignore the warning, the site and download are safe[
  • Unzip the folder onto your Desktop
  • Right click on the RegBak64 and select Run as administrator
  • Click New Backup, leave the default Backup Folder setting, and type in BC Backup under Description
  • Click on Click here to view details of the hives in the backup
  • Check Select hives not loaded by Windows
  • Click OK, then Start
  • Once your see Finished successfully click Close
  • Verify the BC Backup folder is present then click Close


Farbar Recovery Scan Tool Fix
  • Right click on the FRST64 icon and select Run as administrator
  • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
  • There is no need to paste the information anywhere, FRST64 will do it for you

Code:
Start::
CreateRestorePoint:
CloseProcesses:

C:\Users\User\AppData\Local\AdaptiRouter.exe

StartRegedit:
Windows Registry Editor Version 5.00
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications\AdaptiRouter.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender]
"DisableAntiSpyware"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection]
"DisableBehaviorMonitoring"="=-
"DisableOnAccessProtection"=-
"DisableScanOnRealtimeEnable"=-
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SecurityHealthService]
"Start"=dword:00000003
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc]
"Start"=dword:00000002
EndRegedit:

Emptytemp:
End::

  • Click Fix
  • Note: The Emptytemp: command will remove cookies and may result in some websites (like banking) indicating they do not recognize your computer. It may be necessary to receive and apply a verification code.
  • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.

In your next reply, please include:
  • RegBak completed..?
  • Fixlog.txt
  • What problems are you seeing..?
 
RegBak completed
Fixlog txt attached

Upon startup, I have a pop-up, entitled Watchdog_Recycle, stating " The system cannot find the file C:\Program Data\Services\Recycle.exe
Windows defender just detected Trojan:Win64/Lazy.PGLI!MTB
(3/22/2026 2:13 AM)

These are the same 2 problems that started on Mar08
 

Attachments

Do you recognize these files..:

Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recycle.bat [57 2026-03-04] () [File not signed]
Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recycle_launcher.hta [301 2026-03-04] () [File not signed]
Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\watchdog_Recycle.lnk [2026-03-04]
ShortcutTarget: watchdog_Recycle.lnk -> C:\ProgramData\Services\watchdog_Recycle.bat () [File not signed]

Farbar Recovery Scan Tool Fix
  • Right click on the FRST64 icon and select Run as administrator
  • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
  • There is no need to paste the information anywhere, FRST64 will do it for you
Code:
Start::
CloseProcesses:

File: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recycle.bat
File: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recycle_launcher.hta
File: C:\ProgramData\Services\watchdog_Recycle.bat

End::
  • Click Fix.
  • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
In your next reply, please include:
  • Fixlog.txt
 
Last edited:
I recognize none of the startup files. The ShortcutTarget is the same one that appears on every startup since the virus first appeared.
Windows defender just detected Trojan:Win64/Lazy.PGLI!MTB
(3/22/2026 11:56 AM)
 

Attachments

Last edited:
Farbar Recovery Scan Tool Fix
  • Right click on the FRST64 icon and select Run as administrator
  • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
  • There is no need to paste the information anywhere, FRST64 will do it for you
Code:
Start::
CreateRestorePoint:
CloseProcesses:

Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\intauthorize.lnk [2026-03-08]
ShortcutTarget: intauthorize.lnk -> C:\ProgramData\com_int_repository_arm64\SCube.exe (Tenorshare Co., Ltd. -> Tenorshare)
Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recycle.bat [57 2026-03-04] () [File not signed]
Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recycle_launcher.hta [301 2026-03-04] () [File not signed]
Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\watchdog_Recycle.lnk [2026-03-04]
ShortcutTarget: watchdog_Recycle.lnk -> C:\ProgramData\Services\watchdog_Recycle.bat () [File not signed]
C:\ProgramData\Services\watchdog_Recycle.bat
C:\Users\User\AppData\Roaming\com_int_repository_arm64
C:\ProgramData\com_int_repository_arm64
C:\ProgramData\ConfigRuntime_win64
C:\Users\User\AppData\Roaming\ConfigRuntime_win64
Shortcut: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\watchdog_Recycle.lnk -> C:\ProgramData\Services\watchdog_Recycle.bat
FirewallRules: [{89EF18B1-5FDC-454B-9FFA-74ED0405D01C}] => (Allow) LPort=32683
FirewallRules: [{EEC780B4-3135-4931-88BE-6B9BEC1EB35E}] => (Allow) LPort=33683
FirewallRules: [{13831C18-0D82-4356-AECB-ABCCEE76E6A6}] => (Allow) LPort=26822
FirewallRules: [{EC24A9E2-1834-47D9-A61F-E392BC0B23AA}] => (Allow) C:\Program Files\iTunes\iTunes.exe => No File

Emptytemp:
End::

  • Click Fix
  • Note: The Emptytemp: command will remove cookies and may result in some websites (like banking) indicating they do not recognize your computer. It may be necessary to receive and apply a verification code.
  • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
In your next reply, please include:
  • Fixlog.txt
 
Full scan completed by Windows Defender: No current threats

I am now also able to log into Facebook, without recaptha bouncing me out.
 
Full scan completed by Windows Defender: No current threats
I am now also able to log into Facebook, without recaptha bouncing me out.

Great..! Let’s do some final checks before we wrap up

Fresh FRST logs
Please run FRST tool once more, and attach for me fresh logs:
  • Double-click on the FRST icon to run it, as you did before. When the tool opens click Yes to disclaimer.
  • Press Scan button and wait for a while.
  • The scanner will produce two logs on your Desktop: FRST.txt and Addition.txt.
  • Please attach these two logs in your next reply.

Scan with SecurityCheck by glax24
  • Temporarily disable Microsoft SmartScreen only if it blocks the download of the software. The program is safe
  • Download SecurityCheck by glax24 from here
  • If SmartScreen blocks the file from running click on More info and Run anyway
  • This tool is safe. Smartscreen is overly sensitive. You can check the VirusTotal scan of the tool from here
  • Right-click with your mouse on the Securitycheck.exe and select "Run as administrator" and reply YES to allow it to run
  • Wait for the scan to finish. It will open a text file named SecurityCheck.txt Close the file. Attach it with your next reply.
  • You can find this file in a folder called SecurityCheck, C:\SecurityCheck\SecurityCheck.txt


ESET Online Scan - ESET Online Scan - Eset Online Scanner will take some time, so be prepared.

ESET Online Scanner
  • Right-click on esetonlinescanner_enu.exe and select Run as Administrator.
  • When the tool opens, click Get Started.
  • Read and accept the license agreement.
  • At the Welcome to ESET Online Scanner window, click Get Started.
  • Select whether you would like to send anonymous data to ESET
  • Note: if you see the "Welcome Back to ESET Online Scanner" screen, click Computer Scan > Full Scan.
  • Click on the Full Scan option.
  • Select Enable ESET to detect and remove potentially unwanted applications, then click Start scan.
  • ESET will now begin scanning your computer. This may take some time.
  • When the scan is finished and if threats have been detected, select Save scan log. Save it to your desktop as eset.txt. Click on Continue.
  • ESET Online Scanner may ask if you'd like to turn on the Periodic Scan feature. Click on Continue.
  • On the next screen, you can leave feedback about the program if you wish. Check the box for Delete application data on closing. If you left feedback, click Submit and continue. If not, Close without feedback.
  • Open the scan log on your desktop (eset.txt) and copy and paste its contents into your next reply

In your next reply, please include:
  • FRST.txt
  • Addition.txt
  • SecurityCheck.txt
  • eset.txt
 
Follow those recommendations :

Malwarebytes version 5.5.1.240 v.5.5.1.240 Warning! Download Update
Microsoft Office Professional Plus 2013 v.15.0.4569.1506 Warning! This software is no longer supported. Please use latest Microsoft Office, Office Online or LibreOffice
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.44.35211 v.14.44.35211.0 Warning! Download Update
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.44.35211 v.14.44.35211.0 Warning! Download Update
Microsoft OneDrive v.26.032.0217.0003 Warning! Download Update
WinRAR 6.24 (64-bit) v.6.24.0 Warning! Download Update
WinRAR 6.24 (32-bit) v.6.24.0 Warning! Download Update
Google Chrome v.146.0.7680.80 Warning! Download Update

For the final:

KpRm by Kernel-panik
  • Download KpRm and save it to your Desktop (see here if you must use Chrome)
Note: If the file is detected as malware it is not and it is safe to download. The detection is a false positive.
  • Right click on the icon and select Run as administrator
  • Click Yes on the Disclaimer
  • Place a check mark in Delete Tools, Create Restore Point, and [font=Roboto, sans-serif]Delete now[/font]
  • Click Run
  • Click OK on All operations are completed
  • KpRm will delete itself from you Desktop and you can either save or remove the report that is generated
  • You are free to remove any other tools/reports still remaining
  • Please copy and paste its contents in your next reply.
 
Status
Not open for further replies.

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top