Windows Defender, "Items Skipped During Scan"

Anonymous
2020-03-10T15:47:27+00:00

I keep getting this notification after quick scans, "Windows Defender skipped an item due to exclusions or network protection settings."

To make this clear: I don't have ANY exclusions, and as far as I'm aware, I haven't changed my network protection settings in the past. 

What's going on? Is this malware, or a bug with the new update? How do I fix this? I want to be reassured that I'm safe, this isn't very reassuring.

EDIT: Thank you to Techradar for bringing this issue to light. If any employees read this, could you perhaps re-title it in a way which doesn't make users feel so endangered by the bug? All of us have come to the conlusion that (especially with MBAM) we should be clear.

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Günter Born 49,461 Reputation points
2020-03-25T08:23:30+00:00

Microsoft has released an update to fix that behavior, see Update KB4052623: Microsoft fixes Defender ScanSkip Bug. See also the marked answer.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments

69 additional answers

Sort by: Oldest
  1. Günter Born 49,461 Reputation points
    2020-03-24T14:03:50+00:00

    What is bizarre is the fact that it doesnt indicate which attempted file was skipped.  This lends to concern as I expected it would show which file it was so that I could confirm.

    I agree and that's what I critizise - it's not really transparent for users and it would have been better, if MS has communicated that move in a blog post (we read blog posts about new icons, but we don't get any hint about such a change). Anyhow, hope my explanation given within my blog post made things now clear and transparent.

    Was this answer helpful?

    0 comments No comments
  2. Günter Born 49,461 Reputation points
    2020-03-24T14:08:00+00:00

     Perhaps the message should say something like, Defender skips network files by design.  However, this makes me think that now hackers have a new target and because Defender does not scan these files, it will NEVER be found until it is too late.  

    Such a message would be helpful. Concering the 2nd topic you raised: There is no risk, as I outlined within my blog post. On a server the AV solution installed on the machine will scan. On a NAS oder a local Network, files might be scanned by the client's AV bevor saving to the network share - and probably also during opening again.

    Was this answer helpful?

    0 comments No comments
  3. Günter Born 49,461 Reputation points
    2020-03-24T14:11:36+00:00

    However, in light of the recent problems MS has had with windows update issues, I don't feel particularly comfortable in continuing with this product.  Last week, I switched to another AV product and thus far have been well satisfied.  However, only time will tell if this new product "makes the grade."

    Ok, it's an individual descision, each user need to do. I'm not in the position to defend the defender - im independant from MS. But as a blogger and Microsoft Answers community moderator for over a decade now, I've seen and reported many incidents related to 'other av products'. 

    So it's a kind of 'pest and cholera' ;-).

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2020-03-24T14:48:38+00:00

    I am very happy with the performance of Defender up until this point and augmented it with a Malwarebytes subscription.

    While this popup is a nuisance, it is tolerable as long as it doesnt indicate a compromise of security and AV protection.

    With that said, I simply need confirmation that the "skipped" items are not skipped by some malicious process which masking as a "network" item to get automatically "excluded".

    As I mentioned, NO network shares and duplicated while offline altogether seems to indicate that something is triggering the "exception" which concerns me.

    I have installed a paid version of Trend Micro and performed a scan and came up clean.  So it doesnt appear to be infected... yet... but perhaps it is an open door.

    I am very concerned that Microsoft hasn't published anything to tell customers NOT to worry.  If Defender is having issues which lends to a need to install a 3rd party AV, then they should just say so.  It's not like they lose anything by this recommendation, but will gain trust from consumers that they are actively pursuing avenues of approach.

    So I am therefore very concerned... but have no intention of departing from my windows platforms.  Defender has gotten better, so I would prefer they just advise us... fix it... then we are all good again.

    Was this answer helpful?

    0 comments No comments