How can I stop unscheduled Windows Defender scans triggered by Windows Update scripts?

Anonym
2022-12-22T12:52:23+00:00

Short version: I have a non-locally triggered windows malware scan running that has been peaking my processor through my system account for the last three days. I drains my battery, it makes every other program lag, it prevents my laptop from idling.

This is not a new problem. I can handle the locally triggered windows scans, because they obey the local group policy. But the forced scans that are triggered through Windows Update cannot be interrupted, and they cannot, if they fail for some reason, be closed or relaunched. I don't know what it is doing now, and I cannot find out on my peasant Home version of Windows. I also - obviously - cannot contact my system administrator who controls these runs, as that is Microsoft.

I don't care why you keep doing these. They are not needed, and they are not helpful. I have been scanning for viruses, I have been meticulously going through my computer trying to find out what /I/ have installed that would cause the computer to constantly run something. And there isn't anything. What I have is a trustedinstaller class system/monitor admin task that cannot be stopped, and that will not obey any group policy, that I /can't even trace/ where was started specifically. I can only deduce that what has been triggered is a trustedinstaller script, and I genuinely thought I had been hacked. Alas - it is just **** you guys.

So now my computer will not stop trying to run this scan in "the background", which means boosting to max processor speed constantly as long as I don't have a trask occupying all cores. And it does not matter what I do with Windows defender, enabling it or disabling it, because my user settings do not have anything to do with this service that was launched.

First of all: stop these antimalware launches from being triggered through Windows Update scripts now. Just drop them now. It does not help, and it frequently breaks the Windows Installation. Not by having any impact on the system files, but by launching a service that then locks, and never completes. Now I cannot stop it, and it will not complete. No program on my computer will have access to it, and cannot interrupt Update from launching them. Stop **** doing this. It's obnoxious, and it should not be done.

Second: Once these are launched, you need to have an escape. If there is no escape for the service, you cannot launch it. Make an escape.

Third: De-elevate the service level of these tasks that are launched. And preferably remove all Defender software from all Windows computers, and allow an install of it as a package that then can be protected. You can then allow this program to have access to the system, if the user so desires it. If they do not, you should not launch them.

Fourth: Do you guys understand what sort of security pitfall this is? If you can spoof an install of a routine like this, you can prevent anything on the computer, including Windows Defender, from ever seeing it. You can make this routine just report anything as legitimate, or just prevent anything from reading what it's doing. It's completely insane.

Fifth: If this issue arises on my plain, non-custom spin of a laptop-install from Lenovo -- where does it not occur? I have had this issue for years on my various devices, but I have always had an option to circumvent the non-existent bs sandboxing Windows has to shut the routine down. But in Windows 11, you've finally managed to avoid that by isolating out the user and admin access accounts from even seeing the system account. So well done - I now have to rely on you to make this go away.

Will you do it, or do I just have to retire Windows for good this time? I cannot in good conscience keep an OS that shortens my battery life from 9-10h to 4h because it happens to want to do something. Ok? It does not work. I've dealt with Windows Surpreme Bullshit OS since WIndows 95b, and my glass is **** full.

Windows for home | Windows 11 | Sikkerhet og personvern

Låst spørsmål. Dette spørsmålet ble overført fra Microsofts kundestøttefelleskap. Du kan stemme på om det er nyttig, men du kan ikke legge til kommentarer eller svar eller følge spørsmålet.

0 kommentarer Ingen kommentarer

7 svar

Sorter etter: Mest nyttig
  1. Anonym
    2022-12-22T21:58:00+00:00

    You're doing this for free? I'm just curious, since the way the support pages are set up makes it impossible for me to contact any other support. You should be paid, because they are pushing issues here that should be dealt with elsewhere.

    Anyway. Yes, the task scheduler works, and there are various conditions for the scans and so on there.

    The problem here was that the triggers and conditions for the windows defender scans in the task scheduler weren't obeyed. Had they been, the scan would have ran outside of active hours and when plugged in. Instead, whatever rule this scan obeyed is not in the task scheduler, and has nothing to do with the "scheduled scan" task. Disabling these has no impact on whether the scan is ran, or whether it stops once it's been triggered.

    Instead, it comes from this: KB2267602. It's a specific definition and signature update, and then a scan. And it runs with the system-privileges. This is routinely done, and it is for example the origin of the widely known "feature" with updates that happen to reboot the computer in the middle of the work-day, for example.

    So in this case, what I got was a task that happily draws as much as the cpu-package can manage to pull, even while on battery. And that stops, intermittently, based on some settings that are not transparent to me on the Home-edition. I can't track the progress, I can't actually let the thing run dedicated to complete the scan. And I don't know if the reason why it had been postponed was that my user-account was locking certain files, for example. My mere admin user level cannot see what this routine is doing. I don't have any event in the log, I can only see these various driver failures popping up over time as the files are crunched. One of them appeared while on the login screen, I'm assuming because some file was not accessed while on the login screen.

    I'm sure you understand that I cannot do anything with this by switching around the settings in the task scheduler. I thought I could get around it by making updates in my group-policy locally to make sure updates don't restart the computer during work-hours. There is, I'm assuming from the nagging of an infinite amount of users, an actual flag for this now, new since about August this year.

    But this script-command launched with elevated privileges will not obey that. That's the problem. It launches the mpcmdrun.exe locally (and may or may not obey exclusions because of that, and so fail to complete). But it launches it with another user account(system) that I can't limit or specify, with preferences that are not accessible.

    And you can't avoid this pre-emptively by forcing windows update to not run during work hours - because these security updates are pushed anyway(you could also pause update, but it will come in eventually). And even if you could stop the updates that are downloaded from installing during active hours, they would still install eventually - and now you have the same issue as before: the task is going stay with you and run the whole workday the day after.

    If your VIP status is worth any pull with any level of Microsoft's update deployment, you need to tell them to stop doing this. This is specially relevant for the "definition updates", and it is relevant for the updates that require restarts. Because you risk having the computer restart in the middle of work, for one. I know that group policies for your organisation can be set here. But for me, with no other group policy, who run updates from the official channel only, I will get these regardless of settings elsewhere. It might burn the battery (and there is no negotiating with this process - you don't have access to even inspect it) when you require it. It might cause damage by toasting the laptop (this is like running prime95 for hours, way above intense compilation runs or rendering). It causes file-locks and lag for no reason. It causes all kinds of invalidation of files and drivers in this case. And of course, Windows just helps itself to processing power and battery I might need as a user.

    Note that it would do this, even if I had a 3rd party virus checker installed. Because these are specific Windows Defender routines that will run anyway. Because: the windows defender is not the problem (for a certain value of that word). The exclusive system-account run of a script ran through windows update deployment is.

    I have kind of lost track of how many times I've reported this now.

    And I'm sure you sort of understand that I can't really guess myself through writing some registry switch settings that may work, if I inject them to the system user. And I likely wouldn't be allowed to change these anyway. And I really can't buy my own enterprise edition, so I can select which updates from my system-admin account I want to push to my user-account on the same laptop.

    This use of system account launches of these scans, as well as the deployment of forced updates with reboots, has to change. Whoever is writing these and deploying them need to find another way. Such as creating tasks for the user-account, and then obeying local policies. Which otherwise, to reiterate, can be set in any amount of different ways, but have no impact on whether the Windows update runs are started or not.

    There's no other way to solve this. I cannot do something to hack my way around it, I cannot circumvent it, even by stopping windows updates entirely (sooner or later, I will run feature updates. It might only be after a clean install, but it will still happen).

    So it has to be done at the deployment level.

    Var dette svaret nyttig?

    0 kommentarer Ingen kommentarer
  2. Anonym
    2022-12-22T20:51:02+00:00

    No I am not a bot, I am a ten year MVP and senior Volunteer Moderator here. I am also not Microsoft but another user like you. This is a peer User forum where we try to help you with problems. Rudeness is not allowed here at all. If you want to complain to Microsoft use the Feedback Hub app in Start Menu where developers are tasked to process consumer feedback. But Microsoft will not even see it here because this is a tech forums where other users try to help with your problems.

    Anything scheduled on your PC will be in the Task Scheduler, it cannot be run from Windows Updates which can only possibly and rarely program the Task Scheduler. Here is how to examine it to find the scheduled scan and turn it off:

    https://www.digitalcitizen.life/how-manage-exis...

    I hope it helps. If not I will continue to work with you to find and fix the problem, as long as you are polite.

    Var dette svaret nyttig?

    0 kommentarer Ingen kommentarer
  3. Anonym
    2022-12-22T15:13:12+00:00

    Greg, unless you're an automated posting bot - you're not reading what I'm saying.

    The scan is triggered by an admin-access run task that do not originate locally. They are not planned, they are not scheduled, and they do not obey group policies. They do not complete, or they continuously scan for days, for unknown reasons, but still attempt to launch. This is a returning occurrence, usually because they are trying to set this to run only while "idle". But it basically means that it either continues forever, or it fails to launch. But the service that attempts to launch it keeps going.

    Meanwhile, I can scan no problem using my local windows defender. I haven't changed anything here. I can enable or disable real-time scan (which is an endless waste of energy).

    But this unscheduled, script-triggered event will still launch, and it will be entirely separate from anything else. And so I have something running that I can't actually see on my user-account, but that I can only see as running on the admin/system.

    So no, this has nothing to do with the user-account. It has something to do with the system-account that Wunder-Update is using to launch these obnoxious routines. Note that under Windows 11 I can't even attempt to refuse these updates: they will launch as long as Windows is running.

    edit: Bilde

    Here's another, clean, user account. This launches, and has maintained itself - across multiple boots, attempts to stop all the services, to exclude these orphaned commands -- I cannot do it. It launches and is maintained by the system/admin account, that I don't have access to. So now I'm down to picking out specific updates - which really won't work. Or reinstalling the OS from scratch -- which also won't work, for the same reason: this will again be launched by approved script through Windows Update.

    So now my laptop has been draining battery at an absurd rate for three days. It **** my work, it **** my spare time, and I do not understand why this is even here. This ranks so high on the obnoxiousness scale that it is amazing even for Microsoft. And I knew the guys who did RT. Why even do these scans this way?

    editer: So after deleting all exceptions to scans, reinstalling definition files, disabling quiet times, forcing the laptop to stay awake, forcibly completing a full scan, creating a new account to idle from, all of which it is unknown had any impact on this, the routine finally completed. Before ending, it "recovered" my power-profiles and enabled the high performance scan, invalidated my graphics driver, my chipset drivers, and the keyboard shortcut program and made sure to not recognize my screen driver. I have spent a very long time reinstalling the oem drivers, and putting things back to the way it was.

    This whole process recurs, with minor changes, every time this type of security routine is launched this way. And if I didn't know that the real-time scan causes performance impacts on programs that use the user-profiles for caching - I would now be back to stutter and a dimensional performance hit. If I didn't know the power-profiles may have been the cause of the processor spikes, even after the poor laptop stopped fuming after a full day of scanning -- I would now have about 30% of my battery time compared to before. If I didn't know how to reinstall the graphics drivers properly, I would now be running vga recovery with full brightness on.

    How is this not tested? Why are you launching this on devices that clearly have battery modes and wish to prevent the battery from randomly draining for no reason? If I designed a virus to annoy people to switching to anything else but Windows, I would do this specific thing.

    Var dette svaret nyttig?

    0 kommentarer Ingen kommentarer
  4. Anonym
    2022-12-22T13:32:10+00:00

    Hi Jostein. I'm Greg, here to help you with this.

    There is no group policy in Home version, what's telling you there is?

    If you have Admin errors it's normally a bug. Do you have a Work or School account on the PC? Check in Settings > Accounts > Access Work & School.

    If so then it's referring to Group Policy set by the Administrator of the organization. For this reason I would not have a work or school account on my personal PC, because it can take over with it's Group Policy which is often the same as for the PC's owned by the school or work. You can talk with the IT Admin at your organization to see if they can suggest a workaround, but rarely will they change the policy which may apply to thousands of devices.

    If there is no Work or School account then the next suspect is an overactive antivirus. I would uninstall any 3rd party antivirus in Settings > Apps > Apps & Features and instead run built-in Defender which gives adequate protection, best Windows performance, least issues, and is from Microsoft who knows how to protect their OS best.

    If none of those are responsible then the cause is almost always account corruption. Test for account corruption by creating a new Local Admin account in Settings > Accounts > Family & Other Users > Other Users to see if the problem goes away. Make it an Admin account:

    https://pureinfotech.com/create-local-administr...

    Sign into the new account, test it works correctly, if so move files over, test all apps work or reinstall any that don't. Then when ready delete the old account in Settings > Accounts > Family & Other Users.

    You can also try to Repair the old account by running a Repair Install from the new account, steps here: https://www.elevenforum.com/t/repair-install-wi...

    You can change it to your Microsoft account in Settings > Accounts > Your Info > Sign in with a MS Account Instead.

    Based on the results you post back I may have other suggestions if necessary.

    ______________________________________________

    Standard Disclaimer: There are links to non-Microsoft websites. The pages appear to be providing accurate, safe information. Watch out for ads on the sites that may advertise products frequently classified as a PUP (Potentially Unwanted Products). Thoroughly research any product advertised on the sites before you decide to download and install it.

    Var dette svaret nyttig?

    0 kommentarer Ingen kommentarer
  5. Slettet

    Dette svaret er slettet på grunn av brudd på våre regler for god oppførsel. Svaret ble manuelt rapportert eller identifisert gjennom automatisert gjenkjenning før handlingen ble utført. Se våre regler for god oppførsel for mer informasjon.


    Kommentarer er deaktivert. Finn ut mer