Windows 10: New Windows Defender

Discus and support New Windows Defender in AntiVirus, Firewalls and System Security to solve the problem; I cant get the new WD Security Center to scan just one file like the old one did. 82004 Discussion in 'AntiVirus, Firewalls and System Security' started by Clint, Apr 14, 2017.

  1. Clint Win User

    New Windows Defender


    I cant get the new WD Security Center to scan just one file like the old one did.

    :)
     
    Clint, Apr 14, 2017
    #1
  2. Smorboll Win User

    Will Windows 10 NEW Version (April, 2017) have an improved version of Windows defender?

    Windows Defender does catch most malware, however many do get through. Windows Defender constantly receives updates to its definitions. The new Windows Defender has a new user interface, but I do not believe the new Windows Defender has any major definition
    update, other than the almost-daily updates as of currently.
     
    Smorboll, Apr 14, 2017
    #2
  3. Windows Defender Offline for Windows 10

    FYI...

    <QP>

    Several new features and management options have been added to Windows Defender in Windows 10, version 1607. [For example,]

    Windows Defender Offline in Windows 10
    can be run directly from within Windows...

    </QP>

    Source:
    https://technet.microsoft.com/en-us/itpro/windows/whats-new/whats-new-windows-10-version-1607#windows-defender


    <QP>

    In Windows 10 [1607], Windows Defender Offline can be run with one click directly from the Windows Defender client...

    </QP>

    Source:
    https://technet.microsoft.com/en-us/itpro/windows/keep-secure/windows-defender-offline
     
    PA Bear - MS MVP, Apr 14, 2017
    #3
  4. Cliff S New Member

    New Windows Defender

    New Windows Defender [​IMG]
     
    Cliff S, Apr 14, 2017
    #4
  5. Clint Win User
    That doesn't work. This is what I get when I R click and choose Scan with WD.

    New Windows Defender [​IMG]


    New Windows Defender [​IMG]
     
    Clint, Apr 14, 2017
    #5
  6. swarfega Win User
    It ends up at that screen after doing the file scan. It could be made clearer what's happening in my view.
     
    swarfega, Apr 14, 2017
    #6
  7. Brink
    Brink New Member
    Brink, Apr 14, 2017
    #7
  8. Clint Win User

    New Windows Defender

    Brink, I get that screen on every file that I try to scan. It always shows 2 files. I download the reg file in option 2 It does the same.
     
    Clint, Apr 15, 2017
    #8
  9. Bree New Member
    I've tried a Defender scan on various files, including a .png (1 file scanned), .txt (1), Add_Scan_with_Windows_Defender-UI.reg (3) and Reset_Microsoft_Edge.zip from this tutorial (3). That last one is informative, because if I extract the .ps1 file it contains and scan that it then says 2 files were scanned.

    The number of 'files' scanned seems to depend on what Defender finds looking inside the file, and what else may need to be scanned as a consequence. In the case of the zip v. extracted file, the zip container would be the one extra file in the first scan. Typically Defender will individually scan every file packed inside a .exe that is a Setup package.

    Exactly what type of file are you trying to scan?



    Edit: I have just restored the 1607 image for my test machine (System Two in my 'specs') and scanned the same 'Reset_Microsoft_Edge.zip' as above. This said 2 items for the .zip file, one when scanning the extracted .ps1.

    It may be that the Creators' Defender has new functions to scan 'system' related items if found in such text-based files.
     
  10. Works fine here Clint and never seen this bug + not able to reproduce it. See if the old user interface may cause this, never know? In Task Manager/Details/MSASCuiL.exe/End task/End Process.

    Regards,
     
    MikeMecanic, Apr 15, 2017
    #10
  11. Bree New Member
    @Clint, I have a full explanation of 'why' (it is actually correct behaviour) and a simple 'how' that will fix it.

    On my Creators Update the old and the new UI show the same number 'two' with a custom scan of a folder containing the single file Reset_Microsoft_Edge.ps1


    New Windows Defender [​IMG]



    However, I have discovered how to turn this file into a file that Defender sees as only being one file/item. The clue was when I copied to a USB to scan it on another machine, the copy only scanned as one item - even when copied back to the original machine. This was because the file was no longer marked as 'This file came from another computer and may be blocked to help protect this computer'.

    The way a file is blocked is that it has a Zone Identifier recorded in an alternate data stream. This is an independent data stream alongside the file contents data. Alternate data streams have been a feature of the ntfs file system since XP. You can read it with the Streams utility from Sysinternals.

    Code: C:\TEMP>streams Reset_Microsoft_Edge.ps1 Streams v1.56 - Enumerate alternate NTFS data streams Copyright (C) 1999-2007 Mark Russinovich Sysinternals - www.sysinternals.com C:\TEMP\Reset_Microsoft_Edge.ps1: :Zone.Identifier:$DATA 72[/quote]

    Defender was quite correct in saying it had scanned two files - the first was the content of the file and the second was the alternate data stream.

    Copying this 'blocked' file to an ntfs formatted USB and scanning it with Defender on a 1607 PC again shows two items were scanned. This is not a new feature or bug. It is correct behaviour and has always been that way.

    Bottom line: All 'blocked' files will have two items for Defender to scan. You can remove the second by unblocking the file.
     
  12. Clint Win User
    Well, I guess every thing is alright then. Thanks to all that replied. I will mark it solved.
     
    Clint, Apr 5, 2018
    #12
Thema:

New Windows Defender

Loading...
  1. New Windows Defender - Similar Threads - Defender

  2. Mi Windows Defender hizo la deteccion de un virus troyano, y aparecio primero como amenaza...

    in Windows 10 Gaming
    Mi Windows Defender hizo la deteccion de un virus troyano, y aparecio primero como amenaza...: Hola, descargue un archivo y el Windows Defender me mando automaticamente la alerta de Virus, me dijo que habia detectado un Troyano:Win32/Wacatac.H!ml este archivo al principio aparecia "en cuarentena", luego de un momento a otro Windows me aparecio que restaurarlo, busque...
  3. Mi Windows Defender hizo la deteccion de un virus troyano, y aparecio primero como amenaza...

    in Windows 10 Software and Apps
    Mi Windows Defender hizo la deteccion de un virus troyano, y aparecio primero como amenaza...: Hola, descargue un archivo y el Windows Defender me mando automaticamente la alerta de Virus, me dijo que habia detectado un Troyano:Win32/Wacatac.H!ml este archivo al principio aparecia "en cuarentena", luego de un momento a otro Windows me aparecio que restaurarlo, busque...
  4. Is it safe to let Windows Defender automatically remove quarantined threats?

    in AntiVirus, Firewalls and System Security
    Is it safe to let Windows Defender automatically remove quarantined threats?: Hi, this is my first time encountering a threat on my Windows laptop. Windows Defender detected a threat, quarantined it, and said it "will be removed automatically." I also ran a full scan afterward, and it found no new threats.My question is:Do I need to manually remove the...
  5. Is it safe to let Windows Defender automatically remove quarantined threats?

    in Windows 10 Gaming
    Is it safe to let Windows Defender automatically remove quarantined threats?: Hi, this is my first time encountering a threat on my Windows laptop. Windows Defender detected a threat, quarantined it, and said it "will be removed automatically." I also ran a full scan afterward, and it found no new threats.My question is:Do I need to manually remove the...
  6. Is it safe to let Windows Defender automatically remove quarantined threats?

    in Windows 10 Software and Apps
    Is it safe to let Windows Defender automatically remove quarantined threats?: Hi, this is my first time encountering a threat on my Windows laptop. Windows Defender detected a threat, quarantined it, and said it "will be removed automatically." I also ran a full scan afterward, and it found no new threats.My question is:Do I need to manually remove the...
  7. Hi,my problem is windows defender security has disabled my computer,

    in Windows 10 Gaming
    Hi,my problem is windows defender security has disabled my computer,: It says to call Microsoft windows 1-877-419-6536. I tried using control shift escape but its not working. The background shows my windows security page with red X's on all the headings, and I have no control of my mouse. What can I do?...
  8. Hi,my problem is windows defender security has disabled my computer,

    in Windows 10 Software and Apps
    Hi,my problem is windows defender security has disabled my computer,: It says to call Microsoft windows 1-877-419-6536. I tried using control shift escape but its not working. The background shows my windows security page with red X's on all the headings, and I have no control of my mouse. What can I do?...
  9. where i can find windows defender version 1.427.485.0

    in Windows 10 Gaming
    where i can find windows defender version 1.427.485.0: where i can find windows defender version 1.427.485.0 https://answers.microsoft.com/en-us/windows/forum/all/where-i-can-find-windows-defender-version-14274850/0e530041-4e84-4c22-8375-41f24d138efd
  10. where i can find windows defender version 1.427.485.0

    in Windows 10 Software and Apps
    where i can find windows defender version 1.427.485.0: where i can find windows defender version 1.427.485.0 https://answers.microsoft.com/en-us/windows/forum/all/where-i-can-find-windows-defender-version-14274850/0e530041-4e84-4c22-8375-41f24d138efd