How can I stop unscheduled Windows Defender scans triggered by Windows Update scripts?

Anonym
2022-12-22T12:52:23+00:00

Short version: I have a non-locally triggered windows malware scan running that has been peaking my processor through my system account for the last three days. I drains my battery, it makes every other program lag, it prevents my laptop from idling.

This is not a new problem. I can handle the locally triggered windows scans, because they obey the local group policy. But the forced scans that are triggered through Windows Update cannot be interrupted, and they cannot, if they fail for some reason, be closed or relaunched. I don't know what it is doing now, and I cannot find out on my peasant Home version of Windows. I also - obviously - cannot contact my system administrator who controls these runs, as that is Microsoft.

I don't care why you keep doing these. They are not needed, and they are not helpful. I have been scanning for viruses, I have been meticulously going through my computer trying to find out what /I/ have installed that would cause the computer to constantly run something. And there isn't anything. What I have is a trustedinstaller class system/monitor admin task that cannot be stopped, and that will not obey any group policy, that I /can't even trace/ where was started specifically. I can only deduce that what has been triggered is a trustedinstaller script, and I genuinely thought I had been hacked. Alas - it is just **** you guys.

So now my computer will not stop trying to run this scan in "the background", which means boosting to max processor speed constantly as long as I don't have a trask occupying all cores. And it does not matter what I do with Windows defender, enabling it or disabling it, because my user settings do not have anything to do with this service that was launched.

First of all: stop these antimalware launches from being triggered through Windows Update scripts now. Just drop them now. It does not help, and it frequently breaks the Windows Installation. Not by having any impact on the system files, but by launching a service that then locks, and never completes. Now I cannot stop it, and it will not complete. No program on my computer will have access to it, and cannot interrupt Update from launching them. Stop **** doing this. It's obnoxious, and it should not be done.

Second: Once these are launched, you need to have an escape. If there is no escape for the service, you cannot launch it. Make an escape.

Third: De-elevate the service level of these tasks that are launched. And preferably remove all Defender software from all Windows computers, and allow an install of it as a package that then can be protected. You can then allow this program to have access to the system, if the user so desires it. If they do not, you should not launch them.

Fourth: Do you guys understand what sort of security pitfall this is? If you can spoof an install of a routine like this, you can prevent anything on the computer, including Windows Defender, from ever seeing it. You can make this routine just report anything as legitimate, or just prevent anything from reading what it's doing. It's completely insane.

Fifth: If this issue arises on my plain, non-custom spin of a laptop-install from Lenovo -- where does it not occur? I have had this issue for years on my various devices, but I have always had an option to circumvent the non-existent bs sandboxing Windows has to shut the routine down. But in Windows 11, you've finally managed to avoid that by isolating out the user and admin access accounts from even seeing the system account. So well done - I now have to rely on you to make this go away.

Will you do it, or do I just have to retire Windows for good this time? I cannot in good conscience keep an OS that shortens my battery life from 9-10h to 4h because it happens to want to do something. Ok? It does not work. I've dealt with Windows Surpreme Bullshit OS since WIndows 95b, and my glass is **** full.

Windows for home | Windows 11 | Sikkerhet og personvern

Låst spørsmål. Dette spørsmålet ble overført fra Microsofts kundestøttefelleskap. Du kan stemme på om det er nyttig, men du kan ikke legge til kommentarer eller svar eller følge spørsmålet.

0 kommentarer Ingen kommentarer

7 svar

Sorter etter: Mest nyttig
  1. Anonym
    2023-01-05T14:29:35+00:00

    I think I just installed gpedit through dism. Just to point this out, I didn't do this to change the behaviour of the group-policy, but to try to find out if I had a local rule starting these scans. I expected to find one in either the registry or the group-policy set, but... couldn't find any. I half expected Windows update to have set new temporary rules, but didn't find that either. Meanwhile, you actually can successfully set these flags here, for when to allow the scans, and when to allow updates to install -- and they are respected by /most/ of the update runs(in the same way as the user-available settings that are hidden in fifty different places in Win11 now).

    But not these specific script-runs. And that's more or less when I blew my top here. I had suspected before that there is a one-shot command-line trigger for the Windows defender scans coming in with the "security" updates. Because I keep seeing these updates being downloaded and triggered without any logs of what it is. But I thought it would have "su"-ed assumed the currently running user and launched the scan or whatever that way. Which then would have obeyed active hours, obeyed exceptions, and not freaked out when a program would be running and preventing it from being scanned, etc.

    The thing is that this is not limited to the scans. I still get the situations when I have pending updates, for example, that then require a reboot. Where the system-account happily reboots my computer with no warning whatsoever during an "inactive" moment - that is, while I'm playing a game, or not doing something that specifically uses an active screen-context to display something. And it basically tells all running apps to close immediately to do the restart.

    Meanwhile, the normal update packages, the ones that I can selectively install if I choose to - they are deferring to user profile settings, and will run happily once the computer is "free", or when you choose. They work just fine, and won't launch until you actually idle.

    But the issue here comes with these critical hotfix pushes that I really can't see specifically. I've had one of these fume the laptop and then forcibly restart it in the middle of an exam (the exam program not being a full screen active context window). I've had a programming IDE open, along with some remote desktop contexts, that have the same issue just being wiped and suddenly restarted at US "night" hours. Imagine having something important going on and the computer just blanks and reboots, with no log of anything other than the device drivers panicking because their parent services are being forced to stop.

    I know for a fact that several users from the same environment on work-provided laptops have the same thing, and that it clearly depended on whether or not the group-policy of your admin-group had, at some point, been added or not.

    So the culprit here is, 99% certain, a script-command running something on default group-policies, from a fresh install, by the way, that are not "set". Where these script-admin people are expecting the work-environment to have been set, in spite of this not being the case for normal users.

    And where most updates, and the normal deploy, obey the local group-policy rules (that Windows makes a huge issue out of you being able to set, by the way). But when the "work group"/system account's group policies are not set, or you haven't logged in with your school/work account at some point, you are running on another group policy setup (that I can't see on the home edition). And these defaults then introduce various issues when the local group policy (which is available to me, because it's part of my local "admin" control) is being ignored.

    My issue here is that I can't document specifically what is being done, because I can't log the system account's activity. I can only see my user-account going haywire. And this is going to reoccur every month or so when these script-deploys are done.

    Meanwhile, I'm sure there are thousands and thousands of users out there who are not aware of this, and think that Windows only breaking down for no reason just once a month is kind of ok. And that if the virus scan is toasting the computer for a month, that just means the computer is extra secure.

    But this is kind of a big problem. Where system components can be changed via script, first of all, and invalidate any amount of driver-installs, and cause any amount of inconsistencies between what is installed and what is approved in the update streams. Or where virus-scans happily start changing settings back to .... well, pre-install-defaults without prompts, or add certain things that then cause issues with current user-settings. Or, when the virus-scans basically think that the running user-programs should be live-monitored with an exclusive, full attention monitor-process that drains system resources for days without stopping, while also failing to complete the scans, which then again perhaps launch exceptions, etc.

    This stuff is insane. And the people writing these scripts have to know that default profiles cause these issues, surely. They have deployed them on thousands of computers, after all, not expecting them to ever be set.

    You mentioned the "IT pro" community.. where this might be elevated, or I might get some help to find out what is going on exactly, and maybe a way to document this specifically, perhaps. I didn't get what you meant by that. Any links or anything would be great.

    Var dette svaret nyttig?

    0 kommentarer Ingen kommentarer
  2. Anonym
    2022-12-22T22:09:03+00:00

    Did you install Group Policy on Home edition, because it's not native. That doesn't always work, which could be your problem. It sure sounds like you're an IT Pro by the way you refer to GP and your users. If so this is the wrong forum. I referred you earlier to the IT Pro forums where they can possibly even get some traction on elevating this. Asking in a consumer forums for IT Pro deployment issues is like going to the doctor for dentistry.

    If the update will not uninstall, and you cannot System Restore and then block it, do you have an image to go back and pro-actively block the Update using Hide Updates tool? https://www.droidwin.com/how-to-stop-only-a-spe...

    I really wish there was more that I can do but those are all the suggestions I have for consumer Windows.

    Var dette svaret nyttig?

    0 kommentarer Ingen kommentarer