Thanks, but I know how to manage normal updates, which I performed August 11. Several posts seemed like people were downloading updates off the usual channel.
Windows Defender Antivirus Network Inspection Service issues since Windows 10 2004 update
I got the 2004 update yesterday and that went well enough otherwise but I am having a problem with the Windows Defender Antivirus Network Inspection Service that I did not have previously.
- I noticed in Event Viewer several Errors that began immediately upon completion of the update last night:
The Microsoft Defender Antivirus Network Inspection Service service depends on the Microsoft Defender Antivirus Network Inspection System Driver service which failed to start because of the following error:
The supplied user buffer is not valid for the requested operation.
- Further inspection has revealed that there is now a problem with Real Time Updates.
Microsoft Defender Antivirus Real-Time Protection feature has encountered an error and failed.
Feature: Network Inspection System
Error Code: 0x8007042c
Error description: The dependency service or group failed to start.
Reason: The system is missing updates that are required for running Network Inspection System. Install the required updates and restart the device.
I've got this error repeatedly (3002).
- I went into security and maintenance to see what was going on with my security settings. That is not showing anything "wrong."
- The Network Inspection Service is configured to manual, not automatic. I can't change this.
- Real-time protection is on, and has been on. On Virus & threat protection settings, all of those are still toggled on, and those settings are the same before and after the upgrade. I haven't tried turning them on and off again yet.
- I already did the August Safety scan, but I downloaded a fresh copy and am re-running it.
- I did dism and sfc checks and they showed no problems that needed repair.
Something is definitely wrong with the install of Windows Defender tho... Help? How do I fix this and stop the errors and get it reconfigured properly. Do I have to reinstall it?
Windows for home | Windows 10 | Security and privacy
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
95 answers
Sort by: Most helpful
-
Anonymous
2020-08-12T22:28:37+00:00 -
Anonymous
2020-08-12T22:26:51+00:00 I can confirm that Update for Microsoft Defender Antivirus antimalware platform - KB4052623 (Version 4.18.2008.4) has solved this issue for me on the machines on which the update was available.
WDNIS starts without issue with Memory Integrity enabled on those systems.
-
Anonymous
2020-08-12T22:23:39+00:00 I have the same issue, and reported it here:
Defender Antivirus Network Inspection Service Fails to Start
Details:
\SystemRoot\system32\drivers\wd\WdNisDrv.sys failed to load
The WdNisSvc service depends on the WdNisDrv service which failed to start because of the following error:
The supplied user buffer is not valid for the requested operation.
At the same time I have a BIOS update issue which I reported here:
Aurora R7 BIOS v1.022 (July 2020) Won't Install
Details:
Can't update Dell BIOS. This July 2020 Dell BIOS update is a critical security update.
Aurora R7 BIOS v1.022 (July 2020) Won't Install
I've tried several times but can't get the Aurora R7 BIOS v1.022 (July 2020) to install.
When I run the BIOS installer it creates a file called amifldrv64.sys in the download directory then dies.
Here's the event viewer entry after trying to install it:
Faulting application name: Alienware_Aurora_R7_1.0.22.exe, version: 1.0.5.0, time stamp: 0x5a0e913f
Faulting module name: Alienware_Aurora_R7_1.0.22.exe, version: 1.0.5.0, time stamp: 0x5a0e913f
Exception code: 0xc0000005
Fault offset: 0x00000000000930b0
Faulting process id: 0x40e4
Faulting application start time: 0x01d670c8d05fb854
Faulting application path: C:\Users\Vulcan\Downloads\Alienware_Aurora_R7_1.0.22.exe
Faulting module path: C:\Users\Vulcan\Downloads\Alienware_Aurora_R7_1.0.22.exe
Report Id: 559b4828-6bbc-4a17-9108-3e00a52538e9
Dell Forum Report: Aurora R7 BIOS v1.022 (July 2020) Won't Install
The BIOS issue is likely unrelated, and Dell should look into that urgently but I put it here just in case it is related because both of these issues are security related and they're both occurring at the same time for me.
I also had a critical BIOS security update that I was not sure if it was related or not, and performed at some point during my "process." My update went smoothly (fortunately). I only discovered that the update existed because I had to do the troubleshooting for the issue I was having. I had checked for BIOS updates about a month ago doing maintenance, and the date on the BIOS update was late July.
I can try to show you where it fit in.
* made bad decision to trust seeing no issues on 2004 update, and allowed update to proceed (yes, i did restore points and all that, i don't think it ultimately mattered)
* found issues in event viewer with 2004 update; dism and sfc report no issues ever
* multiple virus scans with multiple vendors, no issues
* troubleshoot and identify issue with wdnissvc
* post to get help
* realize that core isolation is also not working
* troubleshoot and try to get things working
* finally decide to try to roll back to before update
* attempt to revert to previous system fail, system will not boot
* do restore but save data option
* all SEEMS well, dism and sfc report no issues
* one of the things I install is OEM support tool -- find out about BIOS update needed
* UPDATE BIOS successfully, always fun (ha ha)
* other problems develop, signs of system corruption or who knows what
* clean install with assistance of microsoft support
I cannot say if your BIOS issues are or are not related. And I cannot advise of what to do since I am not a MS expert by any means. I've read that you should do BIOS updates before clean installs but if you can't get it done, I don't know. If you don't have a separate topic about this issue, you could start one and ask how to proceed.
-
Anonymous
2020-08-12T22:20:53+00:00 4.18.2008.4 was ready, upon manual check for updates, for 2 of my machines. KB4566782 was available for all of my machines but it is a separate update and Defender 4.18.2008.4 is not rolled into it.
I am currently updating Defender on those other machines and will report back shortly.
The Defender update is KB4052623.
-
Anonymous
2020-08-12T22:10:29+00:00 So after cooling off a bit the other day, I went for the near-nuclear option and did a clean install of the OS moving to 2004 since the issue exists at 1909 which is where I was anyways. I think I would have to roll back a lot further to avoid it, and there were substantial security enhancements over the last 2 years :P
Doing this cleared most of the problems I was seeing in Event Viewer.
I had a brief scare with Defender Offline Scanner not wanting to launch but it eventually did -- not that it works anyways still with my internal harddrive configuration. This has been broken for 2 years now. But at least it is still broken in the same old way.
The only "new" glitchy thing that I see is within Process Explorer, when running as Admin, there is a weird error text still under the path for Registry and Memory Isolation processes -- but I am beginning to think that is a 2004/process explorer issue.
I can also successfully toggle core isolation on and off at will (at the expense of WdNisSvc running or not). This is likely because whatever other software conflict existed (xtuacpidriver.sys and iocbios2.sys) didn't get reinstalled because I did not reinstall ANY of the OEM bloatware.
So now the "only problem" is that even after the monthly update, Core Isolation and Defender real-time AV don't work at the same time as one another.
As far as I can tell the issue still persists.