Microsoft has released an update to fix that behavior, see Update KB4052623: Microsoft fixes Defender ScanSkip Bug. See also the marked answer.
Windows Defender, "Items Skipped During Scan"
I keep getting this notification after quick scans, "Windows Defender skipped an item due to exclusions or network protection settings."
To make this clear: I don't have ANY exclusions, and as far as I'm aware, I haven't changed my network protection settings in the past.
What's going on? Is this malware, or a bug with the new update? How do I fix this? I want to be reassured that I'm safe, this isn't very reassuring.
EDIT: Thank you to Techradar for bringing this issue to light. If any employees read this, could you perhaps re-title it in a way which doesn't make users feel so endangered by the bug? All of us have come to the conlusion that (especially with MBAM) we should be clear.
Windows for home | Windows 10 | Security and privacy
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
69 additional answers
Sort by: Newest
-
Rob Koch 26,160 Reputation points Volunteer Moderator
2020-03-21T15:05:18+00:00 The IBM Trusteer Rapport software has been around for over a decade and has had a varied history of negative comments by users, though it's sometimes been pushed by various banks around the world that have been having significant issues with fraud and malware capturing passwords.
We've mostly heard about it here relating to issues with stable operation of the web browser and interactions with the Microsoft security products, but it's been a while since I've seen any. This decade old article by KrebsonSecurity, a well known reputable security researcher, gives a good explanation of how the product worked at the time, as well as his thoughts on it's purpose and operation.
A Closer Look at Rapport from Trusteer — Krebs on Security
In general, Trusteer monitors the browser by intercepting calls to the APIs that most malware also use in order to capture passwords or perform other attacks. Since to an antimalware/antivirus program these actions could easily look like the malware that Trusteer is trying to protect against, it's relatively obvious why it's both occasionally detected by them, as well as can sometimes create undesired overhead.
Since that Bkav AV product comes from Vietnam, it's not surprising they might detect this as potential malware, since their customer base isn't likely to use this Trusteer software that's more commonly provided by banks in the Western world.
At the same time, it's worth reading through that Krebs on Security article, since the decision whether to continue using the Trusteer software that IBM acquired shortly after that article is probably more related to its potential misuse and unintended issues than this specific detection.
Along with this, the web browsers have changed drastically since that time to include protections like operating in a sandbox (Edge & Chrome), as well as other protections within the browser, Windows and Defender that perform the sort of monitoring or blocking of the very same attacks that Trusteer was designed to watch for.
In other words, it's a valid question whether Trusteer even has a purpose on a modern Windows 10 system, since the issues it was created to deal with have mostly been resolved or are at least better monitored by the built-in protections that Windows 10 provides.
Rob
-
Anonymous
2020-03-21T07:52:39+00:00 Yes, it does show up as an installed program so the only concern I have is that it never used to show up as being "infected" with a trojan when I ran the process service program before so do wonder what changed to cause it to do so now. I noticed after my original post that the service shows up with a different name in the list when I open Chrome and two scanners flag it...so...one says infected when Edge is open and two say infected when Chrome is open. I am coming to believe that it is not a legitimate infection/trojan but anything related to finance tweaks my interest in finding out. W32 has been around for awhile but you would think (hope?) that IBM wouldn't have a product out there with this issue.
-
Anonymous
2020-03-21T06:56:36+00:00 Just from reading about it here...
https://www.file.net/process/rapportmgmtservice.exe.html
What is RapportMgmtService.exe?
I don't think it is malware. Also, only one anti-virus scanner flagged it for you out of a trillion.
However, I would uninstall it, especially if it is a processor hog as is said in there. Maybe contact your own bank first. I hope it is not a difficult uninstall for you, as it was for someone in there. Does it show up at "START, Settings, Apps"?
-
Anonymous
2020-03-21T05:59:01+00:00 I installed "Process Explorer v16.21" aka www.sysinternals.com and 1 out of 72 search engines (Bkav) shows malware for "Rapport Mgmt Service.exe" (the IBM Trusteer service for banking) . Checking it out, it comes up as "W32.AIDetectVM.malware". I ran Windows Defender and Windows Defender online and both times got the same "Windows Defender skipped and item due to exclusions or network protection settings" and also ran Malware Bytes. All three scans did not find the malware that is "apparently" there...so I do not know if this is a fake hit by Bkav, a problem with Windows Defender, a problem with the IBM product...or what? I have the Trusteer extension added to both Edge and to Chrome but have removed and reinstalled the program and the extensions and the malware hit came back as seen in the screen snip. FYI