(1) Two repair/upgrade-install's is enough for me to say that isn't a cure. A repair/upgrade install seeks to keep settings. So, normally I'd say a setting is implicated. But you also did a reset which doesn't keep settings (I don't think). So it's still a mystery why a Defender offline scan fails. Are you willing to try a clean install? You've got a master willing to help with that in this thread -- Greg!
(2) I doubt it is a virus or malware issue because you've scanned with many scanners. I doubt any more are necessary. But have you got Secure Boot enabled in BIOS? That one checks for rootkit viruses at the earliest possible moment -- before even the recovery environment can be reached.
(3) I'm unsure whether an offline Defender scan checks for anything more than an Online quick scan checks. The only virus definitions mine used were found on C: drive, & there's this line in my MsssWrapper.log**:**"Signatures are already fairly recent. Skipping sig update.". But, if it finds a virus, I guess it would be easier to remove. Also, maybe, since Windows & the virus aren't running, the virus can't hide as well.
(4) I'd still like to know whether you can "Reg Query HKLM\SYSTEM" in the recovery environment (Shift+Restart). It would say whether it is Defender at fault or something about your pre-boot environment itself. But that presumes the Defender pre-boot & the Shift+Restart pre-boot are the same.