Windows Defender Offline scan won't work

Anonymous
2021-03-08T22:48:02+00:00

Hi, I've been having a lot of trouble trying to get Windows Defender to run an offline scan. It restarts the computer and I see the blue screen that says Windows Defender but it never runs the scan and the computer starts up after that. When I checked the Event Viewer it said nothing about Defender finishing the scan and just a lot of events that say that Windows Defender configuration was changed and if this was unexpected that it might be malware. Because of this I reset the laptop and that didn't fix the issue. I ran sfc /scannow plus dism and that didn't fix the issue. I then started running every scan I could using programs like Malwarebytes, rkill, Microsoft malicious software remover tool(I think that's what it's called) and a usb bootable scanner from Kaspersky. None of them found anything that was bad. I read online that if I did a Windows 10 repair upgrade then this fixes the problem most of the time, so that's what I did. After all of this I still can't get Windows Defender offline scan to work. Does anyone know what the issue is?

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

41 answers

Sort by: Most helpful
  1. Anonymous
    2021-03-12T18:02:52+00:00

    Thanks for the reply.

    I double checked and my account is administrator and yes I've tried creating a new account with administrator privileges before but the scan still didn't work so I deleted that account.

    As for what other scans I've run...I ran malwarebytes in safe mode...Windows malicious software remover tool...rkill...and I think it's called kaspersky rescue disk on a bootable usb drive. All of them came back with nothing except Kaspersky found one file that it said wasn't a virus and it was a legitimate file I had downloaded but I deleted it anyways just in case. I just ran adwcleaner and it found two pups in children -internet explorer from dotomi.com. I removed them.

    As for the logs I removed the product and service version because I wasn't sure if they were personal info or not and didn't want them out on the internet but the other version info was just 0.0.0.0 like it shows in the log I posted. Is that unusual?

    My recovery partition is there and windows says it's healthy but I'm not sure about anything else. Here's the info.....

    Windows Recovery Environment (Windows RE) and system reset configuration Information:Windows RE status:EnabledWindows RE location: \?\GLOBALROOT\device\harddisk0\partition4\Recovery\Windows.REBoot Configuration Data (BCD) identifier: (I removed this info in case it's personally identifiable)Recovery image location: 0Recovery image index: 0Custom image location: 0Custom image index: 0

    I have been thinking and wanted to get your opinion on this. Many months ago the computer crashed and I eventually ended up doing a scan of the RAM and it came back saying there was an issue. But since then I have not had any problems. If the RAM is indeed bad could that be causing these issues somehow or do you think it's unrelated?

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2021-03-12T17:53:00+00:00

    Hi, thanks for the help. I have done everything you suggested already except for the adwcleaner. All of the scans I have done found nothing and the repair upgrade didn't fix the problem either. I will run adwcleaner and see if that finds anything and get back to you in that.

    Update: adwcleaner found two pups in children -internet explorer from dotomi.com. I removed them and I am running sfc again. I'm unsure what those are doing in internet explorer as I don't use internet explorer.

    Update: sfc /scannow found no corrupted files and I tried the defender offline scan again and it still didn't work.

    As for the recovery partition it is there, about 1gb in size and it says it's healthy.

    Windows Recovery Environment (Windows RE) and system reset configuration

    Information:

    Windows RE status:

    Enabled

    Windows RE location: \?\GLOBALROOT\device\harddisk0\partition4\Recovery\Windows.RE

    Boot Configuration Data (BCD) identifier: (I removed this info because I'm not sure if it is personal info or not)

    Recovery image location:

    Recovery image index:

    Custom image location:

    Custom image index:

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2021-03-12T07:10:30+00:00

    Hi TT. I'm Greg, awarded MVP for eleven years, Volunteer Moderator, and Independent Advisor here to help you until this is resolved.

    Defender Offline scan will not work if the WIndows 10 Recovery partition is deleted:

    https://www.tenforums.com/antivirus-firewalls-s...

    It also has stopped working for long periods after Version Updates. Mine has never worked. Of course I only rely on Malwarebytes since it gives the most bang for the buck as a scanner.

    There's something recorrupting your System Files after they're replaced by SFC. Here is the protocol for this:

    Download, install and run a full scan with the most powerful on-demand free scanner Malwarebytes:

    https://www.malwarebytes.com/mwb-download/.

    In the Malwarebytes Settings > Security tab set it to include scanning for Rootkits.

    If necessary run it in Safe Mode with Networking, or Safe Mode accessed by one of these methods: https://www.digitalcitizen.life/4-ways-boot-saf...

    Clean up anything found, restart PC and then run again until it comes up clean.

    Then download, install and run a full scan with AdwCleaner:

    http://www.bleepingcomputer.com/download/adwcle... Remove whatever it finds.

    Check for any remainders in Settings > Apps > Apps & Features, and also in each of your browser's Extensions, Home Page settings, Search service or Add-On's as shown here: https://www.computerhope.com/issues/ch001411.htm

    Then check for damaged System files by running System File Checker from Step 10 in this checklist:

    http://answers.microsoft.com/en-us/windows/wiki....

    If completing all of Step 10 in above Checklist doesn't fix it then run a Repair Install which reinstalls WIndows (and the Recovery partition needed by WDO) while keeping your files, programs and most settings in place, by installing the Media Creation Tool from this link http://windows.microsoft.com/en-us/windows-10/m..., open the tool and choose Upgrade This PC Now. This will solve most problems and also bring it up to the latest version which you need anyway and by the most stable method.

    If you want to keep Malwarebytes as an on-demand scanner then you can turn off its Real Time trial version in it's Settings > Account Details tab.

    I hope this helps. Feel free to ask back any questions and let us know how it goes. I will keep working with you until it's resolved.

    ______________________________________________

    Standard Disclaimer: There are links to non-Microsoft websites. The pages appear to be providing accurate, safe information. Watch out for ads on the sites that may advertise products frequently classified as a PUP (Potentially Unwanted Products). Thoroughly research any product advertised on the sites before you decide to download and install it.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2021-03-12T06:27:24+00:00

    What you highlighted in msssWrapper.log seems to be the root problem...

    ERROR 2021/03/10 19:54:22:153 TID:1472 PID:

    Unable to open the offline HKLM SYSTEM hive with 0x80070020

    ERROR 2021/03/10 19:54:22:153 TID:1472 PID:

    Unable to open the target OS HKLM\System hive with 0x80070020

    It can't open a branch in your Registry which it needs to do to get your drive letters right. It looks to me your C: drive was still going to be C: in the pre-boot environment (like mine), but it needs access to the Registry to be sure.

    (1) So, I thought maybe yours wasn't an Administrator account, but I see you checked that out with Claudeeera. But isn't your regular account an Administrator too?

    (2) I suppose Defender does run when you are booted to Windows, & its definitions do update at "Defender, Virus & Threat Protection, Virus & Threat Protection Update". You've mentioned so many other scanners -- is Defender the Online scanner, or is that one of the others?

    (3) Why are version numbers omitted from MPLog? What is your version at "Defender, Settings, About"...

    Image

    But in MPLog it says...

    Signature updated via XCopy on 03-09-2021 02:56:20

    Product Version: 4.18.1907.16384

    Service Version: 4.18.1909.6

    Engine Version: 1.1.17900.7

    AS Signature Version: 1.331.2697.0

    AV Signature Version: 1.331.2697.0

    I'll keep at it, but so far I've got nothing real good to suggest. You've done it all already, including a Reset & a Repair-Install. What a puzzle! I did try a Google of 0x80501002 0x80070020, but came up only with cures for update issues, & none of them made sense for your problem.

    Edit: To investigate whether you've got a Recovery partition (per Greg's post), let's see "right-click START, Disk Management". Use the divider lines in the header to make the columns readable. Scrunch it using the divider line between the panes. Widen it, if necessary, with the right boarder line.

    Also, at an Administrator Command Prompt, enter...

    ReagentC /Info

    Use Ctrl-A & Ctrl-C to copy, then paste it to us. But, if that says yours is disabled, try: "ReagentC /Enable", presuming you've got the partition. Do another "/Info" to see whether it did enable. If so, try the scan.

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2021-03-11T20:04:20+00:00

    Thank you for all your suggestions!

    Was this answer helpful?

    0 comments No comments