Defender will update in the background as well as the update agent. These a/v file updates are designed to install in the background (as do other a/v updates that is normal for a/v updates) None of these however will kick
a reboot. Can you post your windowsupdate.log file on a onedrive/skydrive as I can check to see what exactly did kick a reboot - as I will state that it wasn't the windows update agent nor was it the def file that would make a system reboot.
Here's the relevant portion of it:
2014-08-02 16:02:04:883 836 518 Shutdwn user declined update at shutdown
2014-08-02 16:02:04:883 836 518 AU Successfully wrote event for AU health state:0
2014-08-02 16:02:04:883 836 518 AU AU initiates service shutdown
2014-08-02 16:02:04:883 836 518 AU ########### AU: Uninitializing Automatic Updates ###########
2014-08-02 16:02:04:898 836 518 Setup Performing pre-shutdown installation of agent
2014-08-02 16:02:04:898 836 518 Report CWERReporter finishing event handling. (00000000)
2014-08-02 16:02:04:898 836 518 Setup Installing setup package "WUClient-SelfUpdate-Aux-TopLevel~31bf3856ad364e35~amd64~~7.6.7600.320"
2014-08-02 16:02:12:417 836 518 Setup Install of setup package "WUClient-SelfUpdate-Aux-TopLevel~31bf3856ad364e35~amd64~~7.6.7600.320" succeeded and requires reboot
2014-08-02 16:02:12:527 836 518 Service *********
2014-08-02 16:02:12:527 836 518 Service ** END ** Service: Service exit [Exit code = 0x240001]
2014-08-02 16:02:12:527 836 518 Service *************
2014-08-02 16:20:42:832 548 6b8 Misc =========== Logging initialized (build: 7.6.7600.256, tz: -0400) ===========
2014-08-02 16:20:42:832 548 6b8 Misc = Process: C:\Windows\system32\rstrui.exe
2014-08-02 16:20:42:832 548 6b8 Misc = Module: C:\Windows\system32\wuapi.dll
2014-08-02 16:20:42:832 548 6b8 COMAPI FATAL: Unable to connect to the service (hr=8007043C)
2014-08-02 16:20:42:832 548 6b8 COMAPI WARNING: Unable to establish connection to the service. (hr=8007043C)
2014-08-02 19:53:44:845 900 19bc Misc =========== Logging initialized (build: 7.6.7600.320, tz: -0400) ===========
That 3hr gap in the timing is where I freaked out thinking I had a virus. It did indeed reboot itself. Shutting down the window I was actively typing in. I have no idea what that "user declined update at shutdown" is.....
When I contacted MS tech support I was basically told there was nothing wrong. Which, sorry, there IS something wrong. Even if this is exactly how MS programmed these software/updates to behave the reaction of people on here shows how wrong it is. How
many more people are freaking out thinking they've picked up a virus cause MS couldn't be bothered to tell people that an update was being forced through?? How many more have interrupted or forced stop on this update and others thinking it was a virus??
I will also add, I have seen no error messages about not being able to install updates, but according to that log there HAVE been attempts to download updates, which have failed. Even though when I tell windows to check for updates it says that there are
none. Nor does it appear to have installed any on its own.