How to Remove Trojan Win32 SuspExec and MSIL ValleyRAT Detections
Question details
The user needs to remove persistent Trojan:Win32/SuspExec.HG!MTB and Trojan:MSIL/ValleyRAT.GZD!MTB malware threats detected by Microsoft Defender.

- Product
- Microsoft Defender
- Device & OS
- Windows
- Scenario
- Microsoft Defender flags potentially harmful files or activities as SuspExec or ValleyRAT during real-time protection or system scans.
- Observed behavior
- The system continuously displays malware alerts for Trojan:Win32/SuspExec.HG!MTB and Trojan:MSIL/ValleyRAT.GZD!MTB, requiring immediate quarantine, removal, and investigation of persistence mechanisms.
Immediately disconnect your computer from the internet (turn off Wi-Fi or unplug the Ethernet cable) to prevent the malware from downloading further payloads or communicating with malicious servers.
Perform a Complete Malware Removal using Windows Defender
The most effective way to eliminate active threats before they load into memory is by running a sequence of Microsoft Defender scans, starting with an offline scan.
Running an offline scan allows Windows Defender to detect and remove malicious software that might attempt to hide or protect itself while the Windows operating system is fully loaded.
Turn off your Wi-Fi or unplug your Ethernet cable to isolate the infected machine from the network.
Navigate to Start > Settings > Update & Security > Windows Security > Virus & threat protection. Click 'Scan options', select 'Microsoft Defender Offline scan', and click 'Scan now'. Your PC will automatically restart and perform a deep scan outside the normal Windows environment.
Once the offline scan completes and Windows boots up, return to the 'Scan options' menu in Windows Security and select 'Full scan' to ensure no remaining malicious files are hidden in your directories.
Go to 'Protection history' in Windows Security to review the detected threats. Ensure all flagged items related to SuspExec or ValleyRAT are permanently removed or quarantined.

Use Microsoft Safety Scanner and Check for Persistence
If the Trojan detections keep returning after a reboot, you must use supplementary tools and manually check for hidden startup tasks that reignite the infection.
Stay Productive and Secure with WPS Office
While securing your PC from Trojans and malware, you also need a reliable, lightweight, and secure suite for your daily document tasks. WPS Office is a completely free Microsoft Office alternative that protects your workflow with robust local encryption, seamless format compatibility, and a familiar user interface.
- 1. Download the Installer: Visit the official WPS Office website and click the download button for Windows.
- 2. Install the Suite: Run the setup file and follow the on-screen instructions to install the application.
- 3. Open Your Documents: Launch WPS Office to securely open, edit, and save your existing Word, Excel, and PowerPoint files.

Frequently Asked Questions
Why does Microsoft Defender keep detecting the same Trojan?
This usually happens if the malware has created a persistence mechanism, such as a scheduled task, startup app, or registry entry, that automatically redownloads or restores the malicious file upon reboot.
Should I reset my PC if the ValleyRAT Trojan won't go away?
Resetting Windows is highly effective if manual removal fails. Go to Settings > System > Recovery > Reset this PC. You can choose to keep your personal files, but all apps and settings will be removed to ensure the malware is completely eradicated.
Is it safe to back up my files while my computer is infected?
Proceed with extreme caution. Only back up essential documents, like PDFs, Word files, or images, to an external drive. Do not back up executable files (.exe, .msi) or scripts, as they may carry the infection to your backup drive.
What is Trojan:Win32/SuspExec.HG!MTB?
It is a heuristic detection by Microsoft Defender indicating a suspicious executable file behaving like a Trojan. It attempts to stealthily execute malicious commands, steal data, or download further malware onto your system.




