Windows Defender Offline scan won't work

Anonymous
2021-03-08T22:48:02+00:00

Hi, I've been having a lot of trouble trying to get Windows Defender to run an offline scan. It restarts the computer and I see the blue screen that says Windows Defender but it never runs the scan and the computer starts up after that. When I checked the Event Viewer it said nothing about Defender finishing the scan and just a lot of events that say that Windows Defender configuration was changed and if this was unexpected that it might be malware. Because of this I reset the laptop and that didn't fix the issue. I ran sfc /scannow plus dism and that didn't fix the issue. I then started running every scan I could using programs like Malwarebytes, rkill, Microsoft malicious software remover tool(I think that's what it's called) and a usb bootable scanner from Kaspersky. None of them found anything that was bad. I read online that if I did a Windows 10 repair upgrade then this fixes the problem most of the time, so that's what I did. After all of this I still can't get Windows Defender offline scan to work. Does anyone know what the issue is?

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

41 answers

Sort by: Most helpful
  1. Anonymous
    2021-03-11T19:51:08+00:00

    I understand, sorry for not being able to solve your problem so far, but don't worry, this is an open forum and another specialist with more ideas can try to help you, bye friend.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2021-03-11T19:42:07+00:00

    Here is the msswrapper log like the one you posted.

    ERROR 2021/03/10 19:54:22:153 TID: PID:

    Unable to open the offline HKLM SYSTEM hive with 0x80070020

    ERROR 2021/03/10 19:54:22:153 TID: PID:

    Unable to open the target OS HKLM\System hive with 0x80070020

    There seems to be some errors in the msswrapper log.

    Here is the mplog

    (Log Removed for privacy)

    Product Version:

    Service Version:

    Engine Version: 0.0.0.0

    AS Signature Version: 0.0.0.0

    AV Signature Version: 0.0.0.0

    ************************************************************

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2021-03-11T19:26:26+00:00

    That's what I thought too. Once I installed Windows 10 over again using the media creation tool (i think it's called that) I figured that would fix the issue but it hasn't. Also, I've run the sfc /scannow and the DISM commands many times and that hasn't fixed the issue either.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2021-03-11T05:28:38+00:00

    Too bad the update was not a fix. I see nothing personal in my logs. I was speaking of the MPLog. Let's see it. But the msssWrapper.log looks interesting too. Post only the date in question. Here was mine...

    START 2021/03/09 02:55:58:223 TID:1412 PID:1380

    INFO 2021/03/09 02:55:58:223 TID:1412 PID:1380

    Loading offline registry library returned 0x00000000

    INFO 2021/03/09 02:55:58:223 TID:1412 PID:1380

    Binary architecture is amd64

    INFO 2021/03/09 02:55:58:239 TID:1412 PID:1380

    UtilIsFileExists(C:\WINDOWS\SysWOW64\ntdll.dll) returned 0x00000000

    INFO 2021/03/09 02:55:58:239 TID:1412 PID:1380

    CheckProcessorArchitecture returned 0x00000000

    INFO 2021/03/09 02:55:58:239 TID:1412 PID:1380

    Setting target OS key: "C:\WINDOWS"

    INFO 2021/03/09 02:55:58:239 TID:1412 PID:1380

    SetRecoveryEnvironmentKey returned 0x00000000

    INFO 2021/03/09 02:55:58:364 TID:1412 PID:1380

    Mapping target OS C drive to WinPE C drive

    INFO 2021/03/09 02:55:58:364 TID:1412 PID:1380

    Mapping target OS D drive to WinPE E drive

    INFO 2021/03/09 02:55:58:395 TID:1412 PID:1380

    BuildTargetOSDriveMapping returned 0x00000000

    INFO 2021/03/09 02:55:58:395 TID:1412 PID:1380

    Searching for signatures. Default signature path: ""

    INFO 2021/03/09 02:55:58:395 TID:1412 PID:1380

    Searching for signatures at root of drives...

    WARNING 2021/03/09 02:55:58:395 TID:1412 PID:1380

    Missing definitions file in 'C:\mpam-fex64.exe'

    WARNING 2021/03/09 02:55:58:395 TID:1412 PID:1380

    Missing definitions file in 'D:\mpam-fex64.exe'

    WARNING 2021/03/09 02:55:58:395 TID:1412 PID:1380

    Missing definitions file in 'E:\mpam-fex64.exe'

    WARNING 2021/03/09 02:55:58:395 TID:1412 PID:1380

    Missing definitions file in 'X:\mpam-fex64.exe'

    INFO 2021/03/09 02:55:58:395 TID:1412 PID:1380

    Searching for signatures from installed product on target OS

    INFO 2021/03/09 02:55:59:598 TID:1412 PID:1380

    Looking for Defender registry key on target OS

    INFO 2021/03/09 02:55:59:598 TID:1412 PID:1380

    Mapped target os path (C:\ProgramData\Microsoft\Windows Defender\Definition Updates{BB2D987A-C198-43B3-ACA0-16E435E4B3B0}) to winpe path (C:\ProgramData\Microsoft\Windows Defender\Definition Updates{BB2D987A-C198-43B3-ACA0-16E435E4B3B0})

    INFO 2021/03/09 02:55:59:598 TID:1412 PID:1380

    Found signatures on the target OS at C:\ProgramData\Microsoft\Windows Defender\Definition Updates{BB2D987A-C198-43B3-ACA0-16E435E4B3B0}

    INFO 2021/03/09 02:55:59:692 TID:1412 PID:1380

    SearchForSignatures returned 0x00000000

    INFO 2021/03/09 02:56:00:911 TID:1412 PID:1380

    Looking for Defender registry key on target OS

    INFO 2021/03/09 02:56:00:911 TID:1412 PID:1380

    Mapped target os path (C:\ProgramData\Microsoft\Windows Defender) to winpe path (C:\ProgramData\Microsoft\Windows Defender)

    INFO 2021/03/09 02:56:01:004 TID:1412 PID:1380

    Initializing offline environment and service...

    INFO 2021/03/09 02:56:03:692 TID:1412 PID:1380

    XCopySignatures returned hr = 0x0

    INFO 2021/03/09 02:56:20:950 TID:1412 PID:1380

    GetTempPathW where sigs would unpack = C:\WINDOWS\Microsoft Antimalware\Tmp\

    INFO 2021/03/09 02:56:20:950 TID:1412 PID:1380

    Signatures are already fairly recent. Skipping sig update.

    INFO 2021/03/09 02:56:20:965 TID:1412 PID:1380

    AS Signature Version: 1.331.2697.0

    INFO 2021/03/09 02:56:20:965 TID:1412 PID:1380

    Engine Version: 1.1.17900.7

    INFO 2021/03/09 02:56:20:965 TID:1412 PID:1380

    Launching user interface...

    INFO 2021/03/09 02:56:20:965 TID:1412 PID:1380

    Auto-scan mode selected...

    INFO 2021/03/09 02:56:20:965 TID:1412 PID:1380

    Registered for notifications

    INFO 2021/03/09 02:56:20:965 TID:1412 PID:1380

    Automatic scan started

    INFO 2021/03/09 02:56:20:965 TID:1412 PID:1380

    Launched Console UI, waiting...

    INFO 2021/03/09 03:03:46:275 TID:1064 PID:1380

    CALLBACK: Scan complete. hResult=0x0, threat count=0

    INFO 2021/03/09 03:03:46:275 TID:1412 PID:1380

    Wait finished (Scan signaled)

    INFO 2021/03/09 03:03:46:275 TID:1412 PID:1380

    Getting results from scan...

    INFO 2021/03/09 03:03:46:275 TID:1412 PID:1380

    Scan completed successfully, attempting to clean any active malware. Number of threats from scan: 0

    INFO 2021/03/09 03:03:46:275 TID:1412 PID:1380

    RunCallisto returned 0x00000000

    INFO 2021/03/09 03:03:46:432 TID:1412 PID:1380

    PreserveCallistoDetections returned 0x00000000

    INFO 2021/03/09 03:03:50:659 TID:1412 PID:1380

    Looking for Defender registry key on target OS

    INFO 2021/03/09 03:04:00:694 TID:1412 PID:1380

    Changes were committed to target OS hive.

    INFO 2021/03/09 03:04:00:804 TID:1412 PID:1380

    SetOfflineScanRunFlag returned 0x00000000

    INFO 2021/03/09 03:04:00:804 TID:1412 PID:1380

    Offline scan completed with 0x00000000

    FINISH 2021/03/09 03:04:00:809 TID:1384 PID:1380

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2021-03-11T03:39:12+00:00

    (1) The offline scan is not run in Windows, so the clock isn't adjusted for DST/whatever else.

    (2) Well, 0x0 normally means there was no error. But that log isn't enormous, Next time, post the whole thing for the date of the run. Mine seems to have 3 distinct sections of that date. I'm unsure the latter 2 relate to the offline run -- but post all you've got. OK, maybe omit that repetitive section about the "exclusion list".

    (3) A new OS Build came in today...

    https://support.microsoft.com/en-us/topic/march-9-2021-kb5000802-os-builds-19041-867-and-19042-867-63552d64-fe44-4132-8813-ef56d3626e14

    March 9, 2021—KB5000802 (OS Builds 19041.867 and 19042.867)

    Click for it at "START, Settings, Update & Security". It should include the goodies of the optional one (...844) you never took. Maybe it will knock some sense into your Defender Offline Scan, even if by accident. Afterward, try the scan, & post the log, if necessary.

    Okay, I checked for the update and Windows installed it today. I tried to run the scan after and the same thing happened that always happens. As for the logs - which log should I post...the mplog or mssswrapper log? Also is there any personal information in there I need to exclude or is it just impersonal info?

    Was this answer helpful?

    0 comments No comments