Windows Defender, "Items Skipped During Scan"

Anonymous
2020-03-10T15:47:27+00:00

I keep getting this notification after quick scans, "Windows Defender skipped an item due to exclusions or network protection settings."

To make this clear: I don't have ANY exclusions, and as far as I'm aware, I haven't changed my network protection settings in the past. 

What's going on? Is this malware, or a bug with the new update? How do I fix this? I want to be reassured that I'm safe, this isn't very reassuring.

EDIT: Thank you to Techradar for bringing this issue to light. If any employees read this, could you perhaps re-title it in a way which doesn't make users feel so endangered by the bug? All of us have come to the conlusion that (especially with MBAM) we should be clear.

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Günter Born 49,461 Reputation points
2020-03-25T08:23:30+00:00

Microsoft has released an update to fix that behavior, see Update KB4052623: Microsoft fixes Defender ScanSkip Bug. See also the marked answer.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments

69 additional answers

Sort by: Oldest
  1. Rob Koch 26,160 Reputation points Volunteer Moderator
    2020-03-15T05:50:29+00:00

    I have over 40 years experience working in the computer field, with nearly half that spent specifically in the security arena.  The quantity of alternative anti-malware testing that you and others have done to try and determine whether your systems are infected tells me that most, if not all, are not.

    Of course, if you're still concerned, you can always wait for confirmation or a fix from Microsoft, most likely to occur with the next cumulative Windows 10 update in early April.  That's easier if you have an additional system available that's not affected by the issue.

    Personally, I've seen these types of minor issues (this is not an error message, just a notification anomaly) dozens of times over the years with security products of all brands.  In fact, those in the security community know that there have been far more critical issues known to exist within many security products used by business and government, some of which remained in place for months, if not years.

    I understand this doesn't make confused consumers feel any safer, but the reality is that is in the scheme of things, this is a minor blip.  Microsoft will announce their findings when there's something to tell you, probably within the supporting information for a future update.

    As an example of what I mentioned above, Windows 10 S mode users had recently spent roughly 3 months experiencing an actual error (update failure) message during monthly updates of the Malicious Software Removal Tool (MSRT).  Though in that case the issue was known and so Microsoft added a small note to the supporting document page for the MSRT explaining that the MSRT wasn't useful with Windows 10 S mode, so the error message didn't matter.

    Despite this messaging, those within the much longer threads similar to this one continued to rant about the error message, but it changed nothing.  Eventually, after 3 months Microsoft apparently fixed whatever was causing the true issue and the errors stopped, though I never saw any additional messaging stating this.

    That's why I indicated you're likely spitting into the wind, since even though that other situation effected absolutely everyone using Windows 10 S mode (most Surface devices and some 3rd-party systems), nothing more than a single sentence was added to a single document explaining that non-issue.  This issue appears even less impactful to a smaller number of systems.

    Rob

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  2. Anonymous
    2020-03-15T11:19:05+00:00

    I ran an online scan with both ESET and Malwarebytes and they found nothing.  I finally decided to purchase a license with Vipre for their AV software.  I ran a thorough scan with that as well and it found no infections.  I feel confident this is just a software bug that will be fixed in the near future.  I probably went "too far" in purchasing a license with a third party vendor, but the recent issues that Microsoft has been having with updates has made me feel less than confident.

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  3. Rob Koch 26,160 Reputation points Volunteer Moderator
    2020-03-15T19:17:16+00:00

    Yes Da Hokester, that was excessive, but it does more to prove the primary point that most here seem to be concerned with, that this notification has nothing to do with a malware infection.

    Again, what that message is indicating is simply that some item(s) have been skipped during manual scanning, either due to an exclusion (which nearly no one seems to have present) or network protection settings.

    This final mention of network protection settings seems the most likely culprit to me, since the existence of any sort of network drive such as a NAS or simply any external drive mapping might be a portion of the cause.  The other portion as you infer is almost certainly due to something in the March Cumulative Windows update, since both the timing and confirmation of this by most here and in that Reddit thread referenced by SleeplessPoster support this belief.

    The key thing to understand here though, is that this notification message is simply that, a notification of items skipped during the scan and noting more.  In truth, this occurs regularly for certain open files or others that for some reason Defender can not access.  However, most of these are well known issues that Defender and all 3rd-party scanners are aware of, so they're designed to ignore them and only display this message for those there's not a known explanation for.

    What's happening since the March Cumulative Windows update is that a few systems appear to be triggering this notification that weren't in the past, likely due to some relatively minor change contained in that code relating to either exclusions or network drives.

    In fact, that just reminded me that I noticed a separate Update for Windows Defender Antimalware Platform when updating a Microsoft Surface Go tablet running Windows 10 S mode this week.  If that same update is installed for all Windows 10 systems, which seems likely, then it's possible the issue was contained in that smaller update.  It might be a good idea for one of those affected by this issue to try uninstalling that Antimalware Platform update to see if this can be confirmed.

    Again, I'm not telling anyone what to do, only possible options to find either the source of the update portion or whatever else on the system such as a network drive might be contributing to the notification.

    For most consumers this is a non-issue, since even if it occurs for everyone performing a manual scan, that's a tiny percentage of users today.  In fact, I haven't personally run a manual scan on any of my own systems for a few months, since that's something that Microsoft itself has only recommended if a recent infection is either known to have occurred or suspected.  That information came directly from the lead Development Project Manager (e.g. lead developer) for both Microsoft Security Essentials and it's predecessor the Windows OneCare security suite.

    People are making way too much of a minor notification anomaly that in all likelihood will just turn out to be an insignificant software bug or interaction.  Before doing something radical like downloading a 3rd-party security program to replace Defender, I'd simply try downloading the tiny (text) Eicar AV test file instead.  If that's flagged as the "severe" threat that's supposed to display from Defender, then real-time protection is working as expected.

    Intended use ° EICAR - European Expert Group for IT-Security

    Remember to turn off SmartScreen in your Microsoft browser before downloading, since otherwise that will intercept the file download before Windows Defender has a chance to see it, though in truth the 2 are integrated tightly so it's likely that SmartScreen is simply handing off the scanning process for Defender to do.

    Rob

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  4. Anonymous
    2020-03-15T20:33:32+00:00

    Hello Rob.  I would like to apologize to you if you felt that my post was in criticism of your post, as that was not really my intent.  But my intent definitely was to express my frustration with Microsoft for seemingly 'dropping the ball' a bit more than my liking when it comes to pushing out updates that cause apprehension about the safety of sensitive data.  Luckily for me, this latest fiasco only affected my 32-bit Windows Pro box.  It did not affect my 64-bit Windows Pro system nor my Windows 10 tablet with Home Edition.  Nonetheless, it is still very frustrating since I regularly use both the 32 and 64 bit systems throughout the day.  Anyway, rest assured that I appreciate the time and effort you sacrificed to respond back, I just regret that my wording might have caused you to think I was taking issue with your advice when, in fact, all I meant to do was emphasize my disgust with the wasted hours and reasonable apprehension that Microsoft's faulty updates cause when dealing with data that is sacrosanct.  Best wishes to you for a good Spring.... and rest of the year too!

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments