Windows Defender Offline scan won't work

Anonymous
2021-03-08T22:48:02+00:00

Hi, I've been having a lot of trouble trying to get Windows Defender to run an offline scan. It restarts the computer and I see the blue screen that says Windows Defender but it never runs the scan and the computer starts up after that. When I checked the Event Viewer it said nothing about Defender finishing the scan and just a lot of events that say that Windows Defender configuration was changed and if this was unexpected that it might be malware. Because of this I reset the laptop and that didn't fix the issue. I ran sfc /scannow plus dism and that didn't fix the issue. I then started running every scan I could using programs like Malwarebytes, rkill, Microsoft malicious software remover tool(I think that's what it's called) and a usb bootable scanner from Kaspersky. None of them found anything that was bad. I read online that if I did a Windows 10 repair upgrade then this fixes the problem most of the time, so that's what I did. After all of this I still can't get Windows Defender offline scan to work. Does anyone know what the issue is?

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

41 answers

Sort by: Oldest
  1. Anonymous
    2021-03-12T23:35:05+00:00

    Okay, I will do that in the future. For right now I  removed the ram stick that was causing the issue just in case. 

    Thanks....I'll also check out the articles about the HDD usage although I'm not surprised by this since it's a budget laptop and pretty slow no matter how I optimize it. I'm sure with a RAM and SSD upgrade it would be much better. For now I'd just love if I could get it working correctly. 

    I'll also check for driver updates but I'm pretty sure they are all up to date as I checked that recently. 

    As for that article.....I've done step 4, step 7, step 10, and also created a new administrator account but the issue still persists after these things. As for step 16 I've looked at the event viewer , especially in regards to defender, but the only events I have that stand out are ID 5007 which I mentioned about in the beginning of this post. I've done a quick scan on the HDD also but that came back fine. I'll take a look at the other steps also and see if I have done those and if not I'll try them out and let you know. 

    I'm really confused as to what can be happening here. I've tried almost everything that is usually recommended but nothing has fixed the defender offline scan. I really just want to figure out if its malware or not but I don't know what other scans to run to find this out. If it comes down to it should I do another repair upgrade with the bad RAM gone and hope that it works the second time? I really don't want to do that again as it took like 5 hours last time but I just want this issue fixed.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2021-03-12T23:55:16+00:00

    Which issue was the RAM stick causing? When running Memtest you can test each stick separately, then test each stick in the other slot to see if the problem is the slot or the stick - it could be either.

    Also examine the slots under bright light and blow any dust out which can affect RAM connection.

    It's possible the RAM if added was not spec'd properly which is why I have users run Crucial scanner because it doesn't make mistakes that I've ever seen.

    Another thing to try is to create a new Local Admin account in Settings > Accounts > Family & Other People > Other Users, as shown here: http://www.howtogeek.com/226540/how-to-create-a...

    https://www.windowscentral.com/how-change-user-...

    Sign into the new account, test if the problem persists. If not move your files over via c:\Users, test all apps run or reinstall them, then when ready delete the old account, and if desired change the new account to your MS account:

    https://www.tenforums.com/tutorials/5464-delete...

    https://www.tenforums.com/tutorials/5375-switch...

    I hope this helps. Feel free to ask back any questions and keep me posted. If you'll wait to rate whether my post resolved your problem, I will keep working with you until it's resolved.

    ______________________________________________

    Standard Disclaimer: There are links to non-Microsoft websites. The pages appear to be providing accurate, safe information. Watch out for ads on the sites that may advertise products frequently classified as a PUP (Potentially Unwanted Products). Thoroughly research any product advertised on the sites before you decide to download and install it.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2021-03-13T00:04:20+00:00

    The RAM came with the laptop and the laptop just crashed the one time and that's when I tested the RAM. I'll try out that test to see if it's the slots or the RAM sticks tho. Thanks for the info. 

    I did create a local admin account and it didn't help with the windows defender offline scan so I deleted it. 

    Looking at this post do you think this might be an answer for me? Is there any way to restore the windows RE? 

    https://answers.microsoft.com/en-us/protect/forum/all/windows-defender-offline-without-function-since/482f0287-3c13-49bc-9827-b89f372b2e5e?page=3

    In the windows defender logs there are two errors......do you know what causes these or how to fix them? 

    ERROR 2021/03/10 19:54:22:153 TID:1472 PID:

    Unable to open the offline HKLM SYSTEM hive with 0x80070020

    ERROR 2021/03/10 19:54:22:153 TID:1472 PID:

    Unable to open the target OS HKLM\System hive with 0x80070020

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2021-03-13T02:37:15+00:00

    WinRe is the same as the Recovery partition. To test if it is functioning (since it is there) try the methods here to get it to boot into Repair Mode (WinRE):

    https://www.tenforums.com/tutorials/2294-advanc...

    You can then go into Advanced Recovery Options (pictured in tutorial link above) to run Startup Repair to check over the boot files.  If it runs then it's intact and functioning.  Exit into Windows.

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2021-03-13T07:04:00+00:00

    (1) Yeah, I think you are an Administrator & even went above & beyond to make a new one; so, it can't be that.

    (2) The closest I get to the meaning of 0x80070020 is in here...

    https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-erref/18d8fbe8-a967-4f1c-ae50-99ca8e491d2d?redirectedfrom=MSDN

    2.2 Win32 Error Codes

    "

    0x00000020<br><br>ERROR_SHARING_VIOLATION The process cannot access the file because it is being used by another process.

    "

    Sometimes the high-order bits (1st half) in an error message can be ignored. But it's impossible to think what can possibly be using your Registry in the pre-boot environment to prevent Defender from using it. It just doesn't make sense. Well, you aren't running Windows from within a VM (Virtual Machine) -- are you? But I know little about that.

    (3) I wasn't totally thorough in my search, but dotomi.com seems to be more of a spy than a virus. Maybe it even causes pop-up ads. I doubt it was the problem, anyway glad you are rid of it. Good going.

    (4) OK, you've got a Recovery partition, & it is enabled. MsssWrapper.log does show access to it probably because Defender will use something inside. Maybe Defender, itself, is in there (I don't know). I do know the version of the tools in the Recovery partition should match or exceed the version of Windows that is installed. But I think yours will match because you've done both a reset & a repair-install. To see your version...

    (a) Click Power, then Shift+Restart to get to the "Choose an Option" screen.

    (b) Click "Troubleshoot > Advanced Options > Command Prompt"

    (c) Try this command...

    Reg Query **HKLM\SYSTEM      <<<**That was the Registry key Defender failed to access. Can you access it?

    (d) Close the Command Prompt, & click "Continue" to return to Windows.

    At the top of the Command Prompt it shows the Windows version. Here in Windows, mine says...

    Microsoft Windows [Version 10.0.19042.867]                <<<20H2 fully updated to OS Build ...867

    (c) 2020 Microsoft Corporation. All rights reserved.

    The OS Build might be lesser in the recovery environment, but that's OK. For me, IIRC, even the version is ...19041... (2004) because I did the mini-upgrade from 2004 to 20H2 through Windows update. That's OK too. You'll likely have ...19042... because you did the reset & that repair-install.

    Here was my  Reg Query while booted to Windows...

    C:\WINDOWS\system32>reg query HKLM\System

    HKEY_LOCAL_MACHINE\System\ActivationBroker

    HKEY_LOCAL_MACHINE\System\ControlSet001

    HKEY_LOCAL_MACHINE\System\DriverDatabase

    HKEY_LOCAL_MACHINE\System\HardwareConfig

    HKEY_LOCAL_MACHINE\System\Input

    HKEY_LOCAL_MACHINE\System\Keyboard Layout

    HKEY_LOCAL_MACHINE\System\Maps

    HKEY_LOCAL_MACHINE\System\MountedDevices

    HKEY_LOCAL_MACHINE\System\ResourceManager

    HKEY_LOCAL_MACHINE\System\ResourcePolicyStore

    HKEY_LOCAL_MACHINE\System\RNG

    HKEY_LOCAL_MACHINE\System\Select

    HKEY_LOCAL_MACHINE\System\Setup

    HKEY_LOCAL_MACHINE\System\Software

    HKEY_LOCAL_MACHINE\System\State

    HKEY_LOCAL_MACHINE\System\WaaS

    HKEY_LOCAL_MACHINE\System\WPA

    HKEY_LOCAL_MACHINE\System\CurrentControlSet

    Was this answer helpful?

    0 comments No comments