Microsoft has released an update to fix that behavior, see Update KB4052623: Microsoft fixes Defender ScanSkip Bug. See also the marked answer.
Windows Defender, "Items Skipped During Scan"
I keep getting this notification after quick scans, "Windows Defender skipped an item due to exclusions or network protection settings."
To make this clear: I don't have ANY exclusions, and as far as I'm aware, I haven't changed my network protection settings in the past.
What's going on? Is this malware, or a bug with the new update? How do I fix this? I want to be reassured that I'm safe, this isn't very reassuring.
EDIT: Thank you to Techradar for bringing this issue to light. If any employees read this, could you perhaps re-title it in a way which doesn't make users feel so endangered by the bug? All of us have come to the conlusion that (especially with MBAM) we should be clear.
Windows for home | Windows 10 | Security and privacy
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
69 additional answers
Sort by: Most helpful
-
Anonymous
2020-03-15T23:22:32+00:00 I do get that message...
...with a manual quick scan or with a full scan. It happens whether/not I turn off Cloud-delivered Protection or Controlled Folder Access. I didn't try the other settings. I've got no folder excluded.
But it did not happen with an Offline Scan. And it hasn't happened after Defender's self-initiated scan, but I'm unsure one has run since the problem began. I'm watching closely for it. But I'm sure more than one has run since 3/10/2020.
It looks like my latest platform came in on 2/24/2020 & is 4.18.2001.10 - but I'm almost willing to swear I saw one come in with those other updates on 2/27 that isn't recorded at View Update History. And I hadn't run a manual scan until yesterday (that I recall). I don't want to say why I ran it, no one else has reported such a thing.
I'm not all that worried. I'll sit tight & see what happens.
Edit: View Reliability History shows the above, plus these two...
And "Windows Defender, Settings, About" shows...
So - Update History is bogus. And two quick ones in a row indicate MSFT tried to fix something but apparently failed. I guess I'll sit tight - & I fully expect a fix soon that will eliminate that message.
-
Rob Koch 26,160 Reputation points Volunteer Moderator
2020-03-15T05:50:29+00:00 I have over 40 years experience working in the computer field, with nearly half that spent specifically in the security arena. The quantity of alternative anti-malware testing that you and others have done to try and determine whether your systems are infected tells me that most, if not all, are not.
Of course, if you're still concerned, you can always wait for confirmation or a fix from Microsoft, most likely to occur with the next cumulative Windows 10 update in early April. That's easier if you have an additional system available that's not affected by the issue.
Personally, I've seen these types of minor issues (this is not an error message, just a notification anomaly) dozens of times over the years with security products of all brands. In fact, those in the security community know that there have been far more critical issues known to exist within many security products used by business and government, some of which remained in place for months, if not years.
I understand this doesn't make confused consumers feel any safer, but the reality is that is in the scheme of things, this is a minor blip. Microsoft will announce their findings when there's something to tell you, probably within the supporting information for a future update.
As an example of what I mentioned above, Windows 10 S mode users had recently spent roughly 3 months experiencing an actual error (update failure) message during monthly updates of the Malicious Software Removal Tool (MSRT). Though in that case the issue was known and so Microsoft added a small note to the supporting document page for the MSRT explaining that the MSRT wasn't useful with Windows 10 S mode, so the error message didn't matter.
Despite this messaging, those within the much longer threads similar to this one continued to rant about the error message, but it changed nothing. Eventually, after 3 months Microsoft apparently fixed whatever was causing the true issue and the errors stopped, though I never saw any additional messaging stating this.
That's why I indicated you're likely spitting into the wind, since even though that other situation effected absolutely everyone using Windows 10 S mode (most Surface devices and some 3rd-party systems), nothing more than a single sentence was added to a single document explaining that non-issue. This issue appears even less impactful to a smaller number of systems.
Rob
-
Rob Koch 26,160 Reputation points Volunteer Moderator
2020-03-14T18:31:24+00:00 Actually ChipmunkLover, you and I agree, you simply took my final sentence as an instruction that you must perform those actions, when what I intended was to let those less knowledgeable about the almost inevitable delays in response know they shouldn't hold their breath.
As those with a background in development like yourself know, a company the size of Microsoft with the literally billions of customer devices and likely millions of slightly different device configurations is highly likely to experience a number of such issues every time a cumulative update is released. Even with a structured testing program like the Windows 10 Insiders, there will be issues discovered after an update that either weren't seen during the testing phase or were rare and not severe enough that they'll be allowed into a release.
This situation appears to be one of those, where an apparently non-critical, but annoying notification is being displayed for a relatively small number of users for an as yet unconfirmed reason.
So I'm not telling anyone they have to do anything, only offering what I believe is a more likely path to determine the potential reason for the notification if they wish, rather then beating their heads against what to me seems an unlikely idea that a non-visible exclusion may be causing the anomaly.
Otherwise, your core advice is sound, just wait for Microsoft to fix it and relax. No one has yet indicated this issue seems to disable Windows Defender's ability to operate or protect a system, only that some are wondering whether it might, To me that seems unlikely and I'd simply ignore it, but how each person deals with this situation is up to them.
Rob
-
Anonymous
2020-03-14T16:19:07+00:00 The fact that most indicating they have this problem don't appear to have an exclusion, along with the nearly certain relationship to the monthly cumulative update, makes me think the cause is something else.
The description for this notification is found in the following document.
Hide notifications from the Windows Security app - Windows security | Microsoft Docs
Item skipped in scan, due to exclusion setting, or network scanning disabled by admin The Windows Defender Antivirus scan skipped an item due to exclusion or network scanning settings. ITEM_SKIPPED Yes Since the exclusion doesn't appear to be the issue, what about the other option of a network scanning setting? In the search for that notification, this earlier thread appeared to have had similar issues due to a possible earlier infection that created an .ISO file mounted as partition G:\
Now I'm not saying this might have been caused by similar past malware, but it does bring to question whether those affected might have additional drives or partitions defined, especially network drives such as a NAS, server or even an ISO file as did the person in that thread?
So rather than beating a dead horse and waiting for Microsoft to respond, which by its very nature won't occur until their developers are certain they've fully explored the potential reasons for the problem and likely delivered the solution as well, you may want to explore the other potential causes as well.
Rob
Rob: Thanks for your input, and without any disrespect intended. and with reference to your final sentence, the real problem for me is I have wasted countless hours of precious time jumping through such hoops only to find later that I was chasing a demon that didn't exist because of a bug in a Microsoft update. One great example of this was the Windows Defender version 4.18.1908.7 update bug. Please understand that I run other operating systems on other boxes and never have wasted time troubleshooting "phantom" problems like I have experienced with Microsoft after bad updates. And for some Windows 10 updates I have even had to disconnect all external USB drives to recover secondary internal hard drives in my Windows 10 box following an update and then reconnect them just to get my system back to normal.
However, I am so heavily invested in coding Office software (including MS Visio and MS Project) for interoperability that relying only on those other OS's is not always pragmatic. In my case, following your advice in your last sentence would only be setting myself up to exacerbate my problem of wasting time, as I have already done my due diligence and eliminated several potential possible causes without question. If Microsoft was a bit more responsive to its consumers, it would be wonderful, but I fear there will be no trend toward that anywhere in the near future.