Windows Defender stopping me from ejecting harddrive

Anonymous
2020-05-26T06:39:44+00:00

After uninstalling Norton (as it came preinstalled after on my computer) I started to experience an issue, whenever I would try to eject my hard drive I would get an error, after looking in event viewer I saw an error talking about how msmpeng.exe was stopping it from ejecting. After researching I found out that this task was windows defender.

However I have tried everything to stop this from happening to no avail, Ive gone into its settings to turn it off and yet it still runs in the background still blocking be from ejecting my hard drive, attempting to close msmpeng.exe in task manager gives me an error that I dont have permission (with no way to change this) I have then followed guides about going into edit to make a file called disablelivespywareprotection (something like that) and now Im out of answers, Am I now forced to just unplug it unsafely or something? please help

Windows for home | Windows 10 | Files, folders, and storage

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

46 answers

Sort by: Most helpful
  1. Anonymous
    2020-11-25T07:30:46+00:00

    @Mean Jim, 

     I have eSATA drives too,  since Microsoft did not fix this bug yet and they seem to be ignoring the complaints ,  in the meantime waiting for a fix, I worked around the problem by adding the devices to the exclusion list as shown in the snap shot below for the defender setting exclusion list.

    Just verify in the event viewer for the system if you get error 225 with the message showing MsMpEng.exe as the program that stopped the removal.

    The application \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.2004.6-0*MsMpEng.exe* with process id 4380 stopped the removal or ejection for the device USB\VID_1058&PID_25FE\575834314131393638334334.

    Assuming that your external devices always have the same letter(s) assigned you can exclude them.

    There is no point on scanning them if they are just backups of internal drives, if there is a bad file to detect it will be detected in the source drive anyway....

    In the sample below, it excludes Drive E:\ and Drive F:\

    Just use the drive letters assigned to your external drives and then reboot.

    This works fine for me, assuming that the culprit is MsMpEng.exe and not some other program or process..

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  2. Anonymous
    2020-11-25T06:29:50+00:00

    I've been having this issue for months with Windows 1909.  It didn't occur very often, but lately it seems to be doing it every time.  I have an eSATA dock with two external drives that I alternate backups to and one USB drive.  It only does it to the eSATA drives.  It seems that the longer the drive is connected, the more likely it is to happen.

    Yesterday I backed up to one of the eSATA drives and the USB drive.  As soon as I turned on the eSATA dock with the drive in it, Windows Defender began scanning it.  The backup took approx. 40 minutes, then I plugged in the USB drive to copy some files from the eSATA drive to the USB drive.  When I was done, Defender was still scanning the eSATA drive.  When I tried to use the safely eject device from the task bar, Defender immediately stopped the scan, yet it still prevented me from ejecting it.

    It did not scan the USB drive at all while plugged in and didn't prevent me from ejecting it.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  3. Anonymous
    2020-11-09T23:18:58+00:00

    Same issue here.

    @_ATOmix_ , 

    Perhaps you should upvote the Feedback Hub report at the link below, maybe MS will do something to fix the problem: 

    https://aka.ms/AA9pb9h

    The Windows Defender platform was changed recently from 4.18.2009.7-0 to 4.18.2010.7-0 on current build 19042.610.

    Tried again with the new platform and got the same problem. 

    Thanks.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  4. Anonymous
    2020-08-12T13:33:12+00:00

    I don't disagree with anything posted here. I am still having some issues with my USB drive having corrupted files and or folders after coping new data to the drive. It could be because Defender is still running and maybe not clearing the new files as safe. I do not know. I've continued to look for ways to get around this issue. Maybe Defender is the problem. And where is msft in all of this??

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  5. Anonymous
    2020-08-08T00:22:04+00:00

    @fg2001

    I use Windows 10 Pro - Version 1909 - OS build: 18363.959 and this Windows Defender problem also occurs on my PC.

    Jose, 

    The quick removal for external drives is already set as default. That is not the issue, when eject is issued they should first stop the activity of windows defender on the drive and then eject correctly.

    If you see the problem also with 1909, that means that they introduced the bug with some recent changes of the defender also in 1909.

    I had 1909 for over a year and never had any problems with eject.

    It all started for me with v 2004 in 5 different machines.

    Also I don't get the problem with any insider development build up to build 20180.

    [Machine Translation]

    @ fg2001,

    Thanks for the answer!

      • Yes, Quick Removal by default is already OK. I posted the link just to show Microsoft's official information about this feature.

    2) - "... If you see the problem also with 1909, that means that they introduced the bug with some recent changes of the defender also in 1909 ..."

    Yes, the USB device removal problem and Windows Defender in version 1909 started recently. Before it worked correctly.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments