Windows Defender Offline scan won't work

Anonymous
2021-03-08T22:48:02+00:00

Hi, I've been having a lot of trouble trying to get Windows Defender to run an offline scan. It restarts the computer and I see the blue screen that says Windows Defender but it never runs the scan and the computer starts up after that. When I checked the Event Viewer it said nothing about Defender finishing the scan and just a lot of events that say that Windows Defender configuration was changed and if this was unexpected that it might be malware. Because of this I reset the laptop and that didn't fix the issue. I ran sfc /scannow plus dism and that didn't fix the issue. I then started running every scan I could using programs like Malwarebytes, rkill, Microsoft malicious software remover tool(I think that's what it's called) and a usb bootable scanner from Kaspersky. None of them found anything that was bad. I read online that if I did a Windows 10 repair upgrade then this fixes the problem most of the time, so that's what I did. After all of this I still can't get Windows Defender offline scan to work. Does anyone know what the issue is?

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

41 answers

Sort by: Newest
  1. Anonymous
    2021-03-11T05:28:38+00:00

    Too bad the update was not a fix. I see nothing personal in my logs. I was speaking of the MPLog. Let's see it. But the msssWrapper.log looks interesting too. Post only the date in question. Here was mine...

    START 2021/03/09 02:55:58:223 TID:1412 PID:1380

    INFO 2021/03/09 02:55:58:223 TID:1412 PID:1380

    Loading offline registry library returned 0x00000000

    INFO 2021/03/09 02:55:58:223 TID:1412 PID:1380

    Binary architecture is amd64

    INFO 2021/03/09 02:55:58:239 TID:1412 PID:1380

    UtilIsFileExists(C:\WINDOWS\SysWOW64\ntdll.dll) returned 0x00000000

    INFO 2021/03/09 02:55:58:239 TID:1412 PID:1380

    CheckProcessorArchitecture returned 0x00000000

    INFO 2021/03/09 02:55:58:239 TID:1412 PID:1380

    Setting target OS key: "C:\WINDOWS"

    INFO 2021/03/09 02:55:58:239 TID:1412 PID:1380

    SetRecoveryEnvironmentKey returned 0x00000000

    INFO 2021/03/09 02:55:58:364 TID:1412 PID:1380

    Mapping target OS C drive to WinPE C drive

    INFO 2021/03/09 02:55:58:364 TID:1412 PID:1380

    Mapping target OS D drive to WinPE E drive

    INFO 2021/03/09 02:55:58:395 TID:1412 PID:1380

    BuildTargetOSDriveMapping returned 0x00000000

    INFO 2021/03/09 02:55:58:395 TID:1412 PID:1380

    Searching for signatures. Default signature path: ""

    INFO 2021/03/09 02:55:58:395 TID:1412 PID:1380

    Searching for signatures at root of drives...

    WARNING 2021/03/09 02:55:58:395 TID:1412 PID:1380

    Missing definitions file in 'C:\mpam-fex64.exe'

    WARNING 2021/03/09 02:55:58:395 TID:1412 PID:1380

    Missing definitions file in 'D:\mpam-fex64.exe'

    WARNING 2021/03/09 02:55:58:395 TID:1412 PID:1380

    Missing definitions file in 'E:\mpam-fex64.exe'

    WARNING 2021/03/09 02:55:58:395 TID:1412 PID:1380

    Missing definitions file in 'X:\mpam-fex64.exe'

    INFO 2021/03/09 02:55:58:395 TID:1412 PID:1380

    Searching for signatures from installed product on target OS

    INFO 2021/03/09 02:55:59:598 TID:1412 PID:1380

    Looking for Defender registry key on target OS

    INFO 2021/03/09 02:55:59:598 TID:1412 PID:1380

    Mapped target os path (C:\ProgramData\Microsoft\Windows Defender\Definition Updates{BB2D987A-C198-43B3-ACA0-16E435E4B3B0}) to winpe path (C:\ProgramData\Microsoft\Windows Defender\Definition Updates{BB2D987A-C198-43B3-ACA0-16E435E4B3B0})

    INFO 2021/03/09 02:55:59:598 TID:1412 PID:1380

    Found signatures on the target OS at C:\ProgramData\Microsoft\Windows Defender\Definition Updates{BB2D987A-C198-43B3-ACA0-16E435E4B3B0}

    INFO 2021/03/09 02:55:59:692 TID:1412 PID:1380

    SearchForSignatures returned 0x00000000

    INFO 2021/03/09 02:56:00:911 TID:1412 PID:1380

    Looking for Defender registry key on target OS

    INFO 2021/03/09 02:56:00:911 TID:1412 PID:1380

    Mapped target os path (C:\ProgramData\Microsoft\Windows Defender) to winpe path (C:\ProgramData\Microsoft\Windows Defender)

    INFO 2021/03/09 02:56:01:004 TID:1412 PID:1380

    Initializing offline environment and service...

    INFO 2021/03/09 02:56:03:692 TID:1412 PID:1380

    XCopySignatures returned hr = 0x0

    INFO 2021/03/09 02:56:20:950 TID:1412 PID:1380

    GetTempPathW where sigs would unpack = C:\WINDOWS\Microsoft Antimalware\Tmp\

    INFO 2021/03/09 02:56:20:950 TID:1412 PID:1380

    Signatures are already fairly recent. Skipping sig update.

    INFO 2021/03/09 02:56:20:965 TID:1412 PID:1380

    AS Signature Version: 1.331.2697.0

    INFO 2021/03/09 02:56:20:965 TID:1412 PID:1380

    Engine Version: 1.1.17900.7

    INFO 2021/03/09 02:56:20:965 TID:1412 PID:1380

    Launching user interface...

    INFO 2021/03/09 02:56:20:965 TID:1412 PID:1380

    Auto-scan mode selected...

    INFO 2021/03/09 02:56:20:965 TID:1412 PID:1380

    Registered for notifications

    INFO 2021/03/09 02:56:20:965 TID:1412 PID:1380

    Automatic scan started

    INFO 2021/03/09 02:56:20:965 TID:1412 PID:1380

    Launched Console UI, waiting...

    INFO 2021/03/09 03:03:46:275 TID:1064 PID:1380

    CALLBACK: Scan complete. hResult=0x0, threat count=0

    INFO 2021/03/09 03:03:46:275 TID:1412 PID:1380

    Wait finished (Scan signaled)

    INFO 2021/03/09 03:03:46:275 TID:1412 PID:1380

    Getting results from scan...

    INFO 2021/03/09 03:03:46:275 TID:1412 PID:1380

    Scan completed successfully, attempting to clean any active malware. Number of threats from scan: 0

    INFO 2021/03/09 03:03:46:275 TID:1412 PID:1380

    RunCallisto returned 0x00000000

    INFO 2021/03/09 03:03:46:432 TID:1412 PID:1380

    PreserveCallistoDetections returned 0x00000000

    INFO 2021/03/09 03:03:50:659 TID:1412 PID:1380

    Looking for Defender registry key on target OS

    INFO 2021/03/09 03:04:00:694 TID:1412 PID:1380

    Changes were committed to target OS hive.

    INFO 2021/03/09 03:04:00:804 TID:1412 PID:1380

    SetOfflineScanRunFlag returned 0x00000000

    INFO 2021/03/09 03:04:00:804 TID:1412 PID:1380

    Offline scan completed with 0x00000000

    FINISH 2021/03/09 03:04:00:809 TID:1384 PID:1380

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2021-03-11T03:39:12+00:00

    (1) The offline scan is not run in Windows, so the clock isn't adjusted for DST/whatever else.

    (2) Well, 0x0 normally means there was no error. But that log isn't enormous, Next time, post the whole thing for the date of the run. Mine seems to have 3 distinct sections of that date. I'm unsure the latter 2 relate to the offline run -- but post all you've got. OK, maybe omit that repetitive section about the "exclusion list".

    (3) A new OS Build came in today...

    https://support.microsoft.com/en-us/topic/march-9-2021-kb5000802-os-builds-19041-867-and-19042-867-63552d64-fe44-4132-8813-ef56d3626e14

    March 9, 2021—KB5000802 (OS Builds 19041.867 and 19042.867)

    Click for it at "START, Settings, Update & Security". It should include the goodies of the optional one (...844) you never took. Maybe it will knock some sense into your Defender Offline Scan, even if by accident. Afterward, try the scan, & post the log, if necessary.

    Okay, I checked for the update and Windows installed it today. I tried to run the scan after and the same thing happened that always happens. As for the logs - which log should I post...the mplog or mssswrapper log? Also is there any personal information in there I need to exclude or is it just impersonal info?

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2021-03-11T03:32:15+00:00

    Have you downloaded Windows from the official website recently?
    https://www.microsoft.com/en-us/software-downlo...

    As I said that you are installing Windows and soon corrupted files appear, make a clean installation of the system, see if it corrects:
    https://www.microsoft.com/en-us/software-downlo...

    Yes, I used the windows media creation tool (I think it's called) and used that to download windows 10 and install Windows 10. I figured that would fix the issue but it hasn't so far. Then a day or so later I scanned using sfc /scannow and the files are corrupted again but how can that be when I just downloaded Windows 10 and did a fresh install?

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2021-03-10T11:28:41+00:00

    Have you downloaded Windows from the official website recently?

    https://www.microsoft.com/en-us/software-downlo...

    As I said that you are installing Windows and soon corrupted files appear, make a clean installation of the system, see if it corrects:

    https://www.microsoft.com/en-us/software-downlo...

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2021-03-10T03:06:07+00:00

    (1) The offline scan is not run in Windows, so the clock isn't adjusted for DST/whatever else.

    (2) Well, 0x0 normally means there was no error. But that log isn't enormous, Next time, post the whole thing for the date of the run. Mine seems to have 3 distinct sections of that date. I'm unsure the latter 2 relate to the offline run -- but post all you've got. OK, maybe omit that repetitive section about the "exclusion list".

    (3) A new OS Build came in today...

    https://support.microsoft.com/en-us/topic/march-9-2021-kb5000802-os-builds-19041-867-and-19042-867-63552d64-fe44-4132-8813-ef56d3626e14

    March 9, 2021—KB5000802 (OS Builds 19041.867 and 19042.867)

    Click for it at "START, Settings, Update & Security". It should include the goodies of the optional one (...844) you never took. Maybe it will knock some sense into your Defender Offline Scan, even if by accident. Afterward, try the scan, & post the log, if necessary.

    Was this answer helpful?

    0 comments No comments