I understand, sorry for not being able to solve your problem so far, but don't worry, this is an open forum and another specialist with more ideas can try to help you, bye friend.
Windows Defender Offline scan won't work
Hi, I've been having a lot of trouble trying to get Windows Defender to run an offline scan. It restarts the computer and I see the blue screen that says Windows Defender but it never runs the scan and the computer starts up after that. When I checked the Event Viewer it said nothing about Defender finishing the scan and just a lot of events that say that Windows Defender configuration was changed and if this was unexpected that it might be malware. Because of this I reset the laptop and that didn't fix the issue. I ran sfc /scannow plus dism and that didn't fix the issue. I then started running every scan I could using programs like Malwarebytes, rkill, Microsoft malicious software remover tool(I think that's what it's called) and a usb bootable scanner from Kaspersky. None of them found anything that was bad. I read online that if I did a Windows 10 repair upgrade then this fixes the problem most of the time, so that's what I did. After all of this I still can't get Windows Defender offline scan to work. Does anyone know what the issue is?
Windows for home | Windows 10 | Security and privacy
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
41 answers
Sort by: Most helpful
-
Anonymous
2021-03-11T19:51:08+00:00 -
Anonymous
2021-03-11T19:42:07+00:00 Here is the msswrapper log like the one you posted.
ERROR 2021/03/10 19:54:22:153 TID: PID:
Unable to open the offline HKLM SYSTEM hive with 0x80070020
ERROR 2021/03/10 19:54:22:153 TID: PID:
Unable to open the target OS HKLM\System hive with 0x80070020
There seems to be some errors in the msswrapper log.
Here is the mplog
(Log Removed for privacy)
Product Version:
Service Version:
Engine Version: 0.0.0.0
AS Signature Version: 0.0.0.0
AV Signature Version: 0.0.0.0
************************************************************
-
Anonymous
2021-03-11T19:26:26+00:00 That's what I thought too. Once I installed Windows 10 over again using the media creation tool (i think it's called that) I figured that would fix the issue but it hasn't. Also, I've run the sfc /scannow and the DISM commands many times and that hasn't fixed the issue either.
-
Anonymous
2021-03-11T05:28:38+00:00 Too bad the update was not a fix. I see nothing personal in my logs. I was speaking of the MPLog. Let's see it. But the msssWrapper.log looks interesting too. Post only the date in question. Here was mine...
START 2021/03/09 02:55:58:223 TID:1412 PID:1380
INFO 2021/03/09 02:55:58:223 TID:1412 PID:1380
Loading offline registry library returned 0x00000000
INFO 2021/03/09 02:55:58:223 TID:1412 PID:1380
Binary architecture is amd64
INFO 2021/03/09 02:55:58:239 TID:1412 PID:1380
UtilIsFileExists(C:\WINDOWS\SysWOW64\ntdll.dll) returned 0x00000000
INFO 2021/03/09 02:55:58:239 TID:1412 PID:1380
CheckProcessorArchitecture returned 0x00000000
INFO 2021/03/09 02:55:58:239 TID:1412 PID:1380
Setting target OS key: "C:\WINDOWS"
INFO 2021/03/09 02:55:58:239 TID:1412 PID:1380
SetRecoveryEnvironmentKey returned 0x00000000
INFO 2021/03/09 02:55:58:364 TID:1412 PID:1380
Mapping target OS C drive to WinPE C drive
INFO 2021/03/09 02:55:58:364 TID:1412 PID:1380
Mapping target OS D drive to WinPE E drive
INFO 2021/03/09 02:55:58:395 TID:1412 PID:1380
BuildTargetOSDriveMapping returned 0x00000000
INFO 2021/03/09 02:55:58:395 TID:1412 PID:1380
Searching for signatures. Default signature path: ""
INFO 2021/03/09 02:55:58:395 TID:1412 PID:1380
Searching for signatures at root of drives...
WARNING 2021/03/09 02:55:58:395 TID:1412 PID:1380
Missing definitions file in 'C:\mpam-fex64.exe'
WARNING 2021/03/09 02:55:58:395 TID:1412 PID:1380
Missing definitions file in 'D:\mpam-fex64.exe'
WARNING 2021/03/09 02:55:58:395 TID:1412 PID:1380
Missing definitions file in 'E:\mpam-fex64.exe'
WARNING 2021/03/09 02:55:58:395 TID:1412 PID:1380
Missing definitions file in 'X:\mpam-fex64.exe'
INFO 2021/03/09 02:55:58:395 TID:1412 PID:1380
Searching for signatures from installed product on target OS
INFO 2021/03/09 02:55:59:598 TID:1412 PID:1380
Looking for Defender registry key on target OS
INFO 2021/03/09 02:55:59:598 TID:1412 PID:1380
Mapped target os path (C:\ProgramData\Microsoft\Windows Defender\Definition Updates{BB2D987A-C198-43B3-ACA0-16E435E4B3B0}) to winpe path (C:\ProgramData\Microsoft\Windows Defender\Definition Updates{BB2D987A-C198-43B3-ACA0-16E435E4B3B0})
INFO 2021/03/09 02:55:59:598 TID:1412 PID:1380
Found signatures on the target OS at C:\ProgramData\Microsoft\Windows Defender\Definition Updates{BB2D987A-C198-43B3-ACA0-16E435E4B3B0}
INFO 2021/03/09 02:55:59:692 TID:1412 PID:1380
SearchForSignatures returned 0x00000000
INFO 2021/03/09 02:56:00:911 TID:1412 PID:1380
Looking for Defender registry key on target OS
INFO 2021/03/09 02:56:00:911 TID:1412 PID:1380
Mapped target os path (C:\ProgramData\Microsoft\Windows Defender) to winpe path (C:\ProgramData\Microsoft\Windows Defender)
INFO 2021/03/09 02:56:01:004 TID:1412 PID:1380
Initializing offline environment and service...
INFO 2021/03/09 02:56:03:692 TID:1412 PID:1380
XCopySignatures returned hr = 0x0
INFO 2021/03/09 02:56:20:950 TID:1412 PID:1380
GetTempPathW where sigs would unpack = C:\WINDOWS\Microsoft Antimalware\Tmp\
INFO 2021/03/09 02:56:20:950 TID:1412 PID:1380
Signatures are already fairly recent. Skipping sig update.
INFO 2021/03/09 02:56:20:965 TID:1412 PID:1380
AS Signature Version: 1.331.2697.0
INFO 2021/03/09 02:56:20:965 TID:1412 PID:1380
Engine Version: 1.1.17900.7
INFO 2021/03/09 02:56:20:965 TID:1412 PID:1380
Launching user interface...
INFO 2021/03/09 02:56:20:965 TID:1412 PID:1380
Auto-scan mode selected...
INFO 2021/03/09 02:56:20:965 TID:1412 PID:1380
Registered for notifications
INFO 2021/03/09 02:56:20:965 TID:1412 PID:1380
Automatic scan started
INFO 2021/03/09 02:56:20:965 TID:1412 PID:1380
Launched Console UI, waiting...
INFO 2021/03/09 03:03:46:275 TID:1064 PID:1380
CALLBACK: Scan complete. hResult=0x0, threat count=0
INFO 2021/03/09 03:03:46:275 TID:1412 PID:1380
Wait finished (Scan signaled)
INFO 2021/03/09 03:03:46:275 TID:1412 PID:1380
Getting results from scan...
INFO 2021/03/09 03:03:46:275 TID:1412 PID:1380
Scan completed successfully, attempting to clean any active malware. Number of threats from scan: 0
INFO 2021/03/09 03:03:46:275 TID:1412 PID:1380
RunCallisto returned 0x00000000
INFO 2021/03/09 03:03:46:432 TID:1412 PID:1380
PreserveCallistoDetections returned 0x00000000
INFO 2021/03/09 03:03:50:659 TID:1412 PID:1380
Looking for Defender registry key on target OS
INFO 2021/03/09 03:04:00:694 TID:1412 PID:1380
Changes were committed to target OS hive.
INFO 2021/03/09 03:04:00:804 TID:1412 PID:1380
SetOfflineScanRunFlag returned 0x00000000
INFO 2021/03/09 03:04:00:804 TID:1412 PID:1380
Offline scan completed with 0x00000000
FINISH 2021/03/09 03:04:00:809 TID:1384 PID:1380
-
Anonymous
2021-03-11T03:39:12+00:00 (1) The offline scan is not run in Windows, so the clock isn't adjusted for DST/whatever else.
(2) Well, 0x0 normally means there was no error. But that log isn't enormous, Next time, post the whole thing for the date of the run. Mine seems to have 3 distinct sections of that date. I'm unsure the latter 2 relate to the offline run -- but post all you've got. OK, maybe omit that repetitive section about the "exclusion list".
(3) A new OS Build came in today...
March 9, 2021—KB5000802 (OS Builds 19041.867 and 19042.867)
Click for it at "START, Settings, Update & Security". It should include the goodies of the optional one (...844) you never took. Maybe it will knock some sense into your Defender Offline Scan, even if by accident. Afterward, try the scan, & post the log, if necessary.
Okay, I checked for the update and Windows installed it today. I tried to run the scan after and the same thing happened that always happens. As for the logs - which log should I post...the mplog or mssswrapper log? Also is there any personal information in there I need to exclude or is it just impersonal info?