Windows Defender Offline scan won't work

Anonymous
2021-03-08T22:48:02+00:00

Hi, I've been having a lot of trouble trying to get Windows Defender to run an offline scan. It restarts the computer and I see the blue screen that says Windows Defender but it never runs the scan and the computer starts up after that. When I checked the Event Viewer it said nothing about Defender finishing the scan and just a lot of events that say that Windows Defender configuration was changed and if this was unexpected that it might be malware. Because of this I reset the laptop and that didn't fix the issue. I ran sfc /scannow plus dism and that didn't fix the issue. I then started running every scan I could using programs like Malwarebytes, rkill, Microsoft malicious software remover tool(I think that's what it's called) and a usb bootable scanner from Kaspersky. None of them found anything that was bad. I read online that if I did a Windows 10 repair upgrade then this fixes the problem most of the time, so that's what I did. After all of this I still can't get Windows Defender offline scan to work. Does anyone know what the issue is?

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

41 answers

Sort by: Oldest
  1. Anonymous
    2021-03-15T04:33:53+00:00

    Thanks for the reply! Yes, I'm not running a virtual machine. 

    Also thanks for checking out dotomi.com. I really appreciate that!

    Im still checking on the version of the recovery environment and will get back to you on that. But I ran the command to see what HKLM/system entries I have and five of the ones you listed are missing from my computer. Is that odd?

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2021-03-15T05:31:25+00:00

    You are welcome.

    (1) If not a virtual machine, I really can't think why the Registry would be in use in the recovery environment. So, I guess 0x80070020 has to mean something other than what I suspected. But what?

    (2) Well, I want to know whether you can access HKLM\system in the recovery environment. That's what defender seems to want to do. Which five sub-keys are you missing? I suppose Defender is going after a sub-key to that, but msssWrapper.log doesn't precisely say which one. It needs information to do the following  (I suspect)...

    SetRecoveryEnvironmentKey returned 0x00000000

    INFO 2021/03/09 02:55:58:364 TID:1412 PID:1380

    Mapping target OS C drive to WinPE C drive

    INFO 2021/03/09 02:55:58:364 TID:1412 PID:1380

    Mapping target OS D drive to WinPE E drive

    INFO 2021/03/09 02:55:58:395 TID:1412 PID:1380

    BuildTargetOSDriveMapping returned 0x00000000

    Your crash came just before that. It wants to know which drive was C: in Windows, I think. Then the other would be the Recovery partition (which normally doesn't have a letter when booted to Windows).

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2021-03-15T20:23:09+00:00

    Okay, just thought I would let you know. I did another repair upgrade, this time with no updates and only keeping personal files but no apps or settings. I tried the scan again and defender still does the same thing. Also the logs are exactly the same. I'm kind of at a loss as to what to do now. Right now my priority is just making sure this was not a virus or malware causing this issue. Are there any other scans that I haven't already run that you can think of that I can use to be sure my computer is safe? I just need to be able to use that laptop again safely.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2021-03-15T20:24:54+00:00

    Thanks for all your help!

    Okay I did what you said and it ran just fine. At this point I decided to do another repair upgrade, this time with no updates and only keeping personal files but no apps or settings. I tried the scan again and defender still does the same thing. Also the logs are exactly the same. I'm kind of at a loss as to what to do now. Right now my priority is just making sure this was not a virus or malware causing this issue. Are there any other scans that I haven't already run that you can think of that I can use to be sure my computer is safe? I just need to be able to use that laptop again safely.

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2021-03-15T23:30:58+00:00

    (1) Two repair/upgrade-install's is enough for me to say that isn't a cure. A repair/upgrade install seeks to keep settings. So, normally I'd say a setting is implicated. But you also did a reset which doesn't keep settings (I don't think). So it's still a mystery why a Defender offline scan fails. Are you willing to try a clean install? You've got a master willing to help with that in this thread -- Greg!

    (2) I doubt it is a virus or malware issue because you've scanned with many scanners. I doubt any more are necessary. But have you got Secure Boot enabled in BIOS? That one checks for rootkit viruses at the earliest possible moment -- before even the recovery environment can be reached.

    (3) I'm unsure whether an offline Defender scan checks for anything more than an Online quick scan checks.  The only virus definitions mine used were found on C: drive, & there's this line in my MsssWrapper.log**:**"Signatures are already fairly recent. Skipping sig update.". But, if it finds a virus, I guess it would be easier to remove. Also, maybe, since Windows & the virus aren't running, the virus can't hide as well.

    (4) I'd still like to know whether you can "Reg Query HKLM\SYSTEM" in the recovery environment (Shift+Restart). It would say whether it is Defender at fault or something about your pre-boot environment itself. But that presumes the Defender pre-boot & the Shift+Restart pre-boot are the same.

    Was this answer helpful?

    0 comments No comments