https://aka.ms/AA98a8v needs upvotes to escalate the issue
Tried but got a message saying "Your account doesn't have access to this feedback."
Try mine:
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
I got the 2004 update yesterday and that went well enough otherwise but I am having a problem with the Windows Defender Antivirus Network Inspection Service that I did not have previously.
The Microsoft Defender Antivirus Network Inspection Service service depends on the Microsoft Defender Antivirus Network Inspection System Driver service which failed to start because of the following error:
The supplied user buffer is not valid for the requested operation.
Microsoft Defender Antivirus Real-Time Protection feature has encountered an error and failed.
Feature: Network Inspection System
Error Code: 0x8007042c
Error description: The dependency service or group failed to start.
Reason: The system is missing updates that are required for running Network Inspection System. Install the required updates and restart the device.
I've got this error repeatedly (3002).
Something is definitely wrong with the install of Windows Defender tho... Help? How do I fix this and stop the errors and get it reconfigured properly. Do I have to reinstall it?
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
https://aka.ms/AA98a8v needs upvotes to escalate the issue
Tried but got a message saying "Your account doesn't have access to this feedback."
Try mine:
I have the same symptoms on version 1903 build 18362.959 after the automatic updates were applied on August 9, 2020. Apparently, it is not specific to "2004".
Antimalware Client Version: 4.18.2007.8
Engine Version: 1.1.17300.4
Antivirus Version: 1.321.1228.0
Antispyware Version: 1.321.1228.0
After updating to Platform 4.18.2008.4, alongside with KB 4566782, the error messages stopped, the Windows Defender Antivirus Network Inspection Service is up and running on my system. Core isolation is on.
I have the same issue, and reported it here:
Defender Antivirus Network Inspection Service Fails to Start
Details:
\SystemRoot\system32\drivers\wd\WdNisDrv.sys failed to load
The WdNisSvc service depends on the WdNisDrv service which failed to start because of the following error:
The supplied user buffer is not valid for the requested operation.
At the same time I have a BIOS update issue which I reported here:
Aurora R7 BIOS v1.022 (July 2020) Won't Install
Details:
Can't update Dell BIOS. This July 2020 Dell BIOS update is a critical security update.
Aurora R7 BIOS v1.022 (July 2020) Won't Install
I've tried several times but can't get the Aurora R7 BIOS v1.022 (July 2020) to install.
When I run the BIOS installer it creates a file called amifldrv64.sys in the download directory then dies.
Here's the event viewer entry after trying to install it:
Faulting application name: Alienware_Aurora_R7_1.0.22.exe, version: 1.0.5.0, time stamp: 0x5a0e913f
Faulting module name: Alienware_Aurora_R7_1.0.22.exe, version: 1.0.5.0, time stamp: 0x5a0e913f
Exception code: 0xc0000005
Fault offset: 0x00000000000930b0
Faulting process id: 0x40e4
Faulting application start time: 0x01d670c8d05fb854
Faulting application path: C:\Users\Vulcan\Downloads\Alienware_Aurora_R7_1.0.22.exe
Faulting module path: C:\Users\Vulcan\Downloads\Alienware_Aurora_R7_1.0.22.exe
Report Id: 559b4828-6bbc-4a17-9108-3e00a52538e9
Dell Forum Report: Aurora R7 BIOS v1.022 (July 2020) Won't Install
The BIOS issue is likely unrelated, and Dell should look into that urgently but I put it here just in case it is related because both of these issues are security related and they're both occurring at the same time for me.
UPDATED: I resolved the BIOS problem by doing the update from the BIOS itself, Windows was causing it to fail and I'm not sure why because the program was just dying. No other apps were running and it normally updates fine from within Windows so it's an OS issue, not an issue with the BIOS update.
To be clear, yes the WD SES Driver is incompatible with Memory Integrity but that is a separate and unrelated issue to the one discussed herein.
The issue causing the problem discussed in this thread seems to be that the newest Defender Platform Network Inspection Driver, WdNisDrv.sys (Wd here is Windows Defender, not Western Digital), is also incompatible with Memory Integrity even though it doesn't report as such when enabling Memory Integrity or anywhere else that an average user would see. It is only reported in Event Viewer and, if you happen to notice, by virtue of the fact that the service isn't running in Services.msc when Core Isolation/Memory Integrity is enabled.
I have verified that this issue also occurs on systems which have never had external storage, or any Western Digital storage for that matter, attached to them.
Hi, pntless,
Thanks for your continued troubleshooting.
Hard drive info: perhaps anecdotal, but wanted to get it out of the way:
SSD with my OS on it, a main data drive where most things are mapped to (Docs, Downloads, etc etc), and then a Media drive. I don't think any of these are WD drives, and while I do have WD external removable drives, I haven't plugged any in since the system rebuild. I went into device drivers, and didn't see any WD drivers in there.
Bit locker:
Not using drive encryption.
Core Isolation issues:
I do NOT have any additional information underneath the toggle telling me why it failed. I kept searching on the internet and found... Microsoft's Device Guard and Credential Guard Readiness Tool. Took a while to be able to find information on how to use it. Used it.
To the best of my knowledge it was working FINE at the outset of my system rebuild process. I have info in device security of something being stopped from writing to memory on Aug 7 during my system rebuild. (Happens from time to time as you know, with things that could even be trusted.)
Here is information on why it is not working (Not going to include all the things that passed):
Incompatible HVCI Kernel Driver Modules found
Module: xtuacpidriver.sys
Reason: execute pool type count: 12
Module: iocbios2.sys
Reason: execute pool type count: 5
HSTIStatus: False
HSTI validation failed
HyperVisorPresent False
(But
VMMonitorModeExtensions True
VirtualizationFirmwareEnabled True
Virtualization firmware check passed)
====================== Summary ======================
Device Guard / Credential Guard can be enabled on this machine.
Looks like xtuacpidriver.sys has to do with the intel Extreme Tuning Utility. The iocbios2.sys is a windows driver but searching for it brings up results on the previous driver. When I am willing to fight with this MESS more, I can see if this needs to be updated. Or maybe it was updated in 1903/1909 and is messed up. I don't know.
And of course because this update just had to ruin everything, my poking around to try to figure out THIS found the following:
In Process Explorer (yes, running as administrator), Registry and Memory Compression are displaying "The system cannot find the specified file." I have never seen this before. I ran sfc /scannow, it found some problems and fixed them. I reran it until it found no problems. This didn't change what I am seeing in process explorer.
After the machine reset, I did -3- full virus scans with -3- different products. Of course, with how messed up some of the operating system components are, this may not mean anything :P
Really don't know what to do with my machine at this point. Kicking it does not seem productive.