Windows 10: Windows Defender Offline Scan in Windows 10

Discus and support Windows Defender Offline Scan in Windows 10 in Windows 10 Tutorials to solve the problem; How to: Windows Defender Offline Scan in Windows 10 How to Perform a Windows Defender Offline Scan in Windows 10 Windows Defender Offline is now... Discussion in 'Windows 10 Tutorials' started by Cliff S, Feb 27, 2016.

  1. Cliff S New Member

    Windows Defender Offline Scan in Windows 10


    How to: Windows Defender Offline Scan in Windows 10

    How to Perform a Windows Defender Offline Scan in Windows 10


    Windows Defender Offline is now a built-in feature starting in Windows 10 build 14271.

    Windows Defender Offline is an antimalware scanning tool that lets you boot and run a scan from a trusted environment. The scan runs from outside the normal Windows kernel so it can target malware that attempts to bypass the Windows shell, such as viruses and rootkits that infect or overwrite the master boot record (MBR).

    You can use Windows Defender Offline if you suspect a malware infection, or you want to confirm a thorough clean of the endpoint after a malware outbreak.

    In Windows 10, Windows Defender Offline can be run with one click directly from the Windows Defender client. In previous versions of Windows, a user had to install Windows Defender Offline to bootable media, restart the endpoint, and load the bootable media.

    This tutorial will show you how to manually run an offline scan of your PC with Windows Defender Offline in Windows 10.

    You must be signed in as an administrator to be able to scan offline with Windows Defender Offline.

    Windows Defender Offline Scan log files are stored as a MPLog-YYYYMMDD-HHMMSS.log file located in the C:\Windows\Microsoft Antimalware\Support folder.

    You will notice D:\ProgramData\Microsoft\Windows Defender\Offline Scanner towards the top in the opened log file.


    Windows Defender Offline Scan in Windows 10 [​IMG]

    Windows Defender Offline Scan in Windows 10 [​IMG]


    Windows Defender event logs are saved to the file below. You can open it to view the logs in Event Viewer.

    %windir%\System32\winevt\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx


    Windows Defender Offline Scan in Windows 10 [​IMG]

    Windows Defender Offline Scan in Windows 10 [​IMG]




    Contents
    • Option One: To Run a Windows Defender Offline Scan from PowerShell
    • Option Two: To Run a Windows Defender Offline Scan from Command Prompt
    • Option Three: To Run a Windows Defender Offline Scan from Windows Defender Security Center





    OPTION ONE [/i] To Run a Windows Defender Offline Scan from PowerShell
    For more usage options for the Start-MpWDOScan command, see: Start-MpWDOScan


    1 Open an elevated PowerShell.

    2 Copy and paste the Start-MpWDOScan command into the elevated PowerShell, and press Enter.

    3 Go to step 6 in OPTION THREE below.





    OPTION TWO [/i] To Run a Windows Defender Offline Scan from Command Prompt
    For more usage options for the Start-MpWDOScan command, see: Start-MpWDOScan


    1 Open an elevated command prompt.

    2 Copy and paste the PowerShell Start-MpWDOScan command into the elevated command prompt, and press Enter.

    3 Go to step 6 in OPTION THREE below.





    OPTION THREE [/i] To Run a Windows Defender Offline Scan from Windows Defender Security Center
    1 Open Windows Security, and click/tap on the Virus & thread protection icon. (see screenshot below)

    Windows Defender Offline Scan in Windows 10 [​IMG]

    2 Click/tap on the Scan options link under the Current threats section. (see screenshot below)

    Windows Defender Offline Scan in Windows 10 [​IMG]

    3 Select (dot) Windows Defender Offline scan, and click/tap on the Scan now button. (see screenshot below)

    Windows Defender Offline Scan in Windows 10 [​IMG]

    4 Click/tap on Scan. (see screenshot below)

    Windows Defender Offline Scan in Windows 10 [​IMG]

    5 If prompted by UAC, click/tap on Yes. (see screenshot below)

    Windows Defender Offline Scan in Windows 10 [​IMG]

    6 You will now see a message that You're about to be signed out to restart your PC in less than a minute to run the scan offline. (see screenshot below)

    Windows Defender Offline Scan in Windows 10 [​IMG]

    7 When your PC restarts, you will see Windows Defender Offline loading. (see screenshot below)

    It may take a while before this is finished and continues to the next step.


    Windows Defender Offline Scan in Windows 10 [​IMG]

    8 Windows Defender will now automatically perform a quick scan of your PC in the recovery environment. (see screenshot below)

    Your PC will automatically restart when the scan has finished.


    Windows Defender Offline Scan in Windows 10 [​IMG]

    9 When the offline scan has finished, your PC will automatically restart to Windows 10.

    That's it,
    Shawn


    Related Tutorials

    :)
     
    Cliff S, Feb 27, 2016
    #1

  2. WDO Windows Defender Offline

    In Windows 10,
    Windows Defender Offline
    is built into the operating system so it can be run automatically or you can manually ask to perform an offline scan with one click directly from the Windows Defender client.

    When Windows Defender identifies malware which it cannot remove, it will recommend that Windows Defender Offline be run and on the next reboot, Windows Defender Offline will automatically scan and remove the malware, then reboot into Windows 10. This removes
    the need to interact with the Windows Defender Offline product manually but that option is available when you want to run an offline scan at any time. When Windows Defender Offline runs automatically it performs a Quick Scan by default which typically takes
    about 15 minutes to run and then your computer will restart normally.
     
    quietman7 - MVP, Feb 27, 2016
    #2
  3. Windows 10 Defender Full Scan consistently fails and stops responding. Have to power off system to recover. Can I download a new version of Defender?

    There's no way to download a new version, but you could try an offline scan as shown here:

    Windows 10:
    Windows Defender Offline Scan in Windows
     
    Shawn 'Cmdr' Keene [MVP], Feb 27, 2016
    #3
  4. Cliff S New Member

    Windows Defender Offline Scan in Windows 10

    Before offline scan in preperation

    Windows Defender Offline Scan in Windows 10 [​IMG]



    Windows Defender Offline Scan in Windows 10 [​IMG]


    After offline scan



    Windows Defender Offline Scan in Windows 10 [​IMG]



    Windows Defender Offline Scan in Windows 10 [​IMG]



    Windows Defender Offline Scan in Windows 10 [​IMG]
     
    Cliff S, Feb 27, 2016
    #4
  5. Cliff S New Member
    Final results

    Windows Defender Offline Scan in Windows 10 [​IMG]
     
    Cliff S, Feb 27, 2016
    #5
  6. Cliff S New Member
    I found the Offline Scanner folder: C:\ProgramData\Microsoft\Windows Defender\Offline Scanner
    Here is the EULA:
     
    Cliff S, Feb 27, 2016
    #6
  7. Cliff S New Member
    Also MpSwpHelp:

     
    Cliff S, Feb 27, 2016
    #7
  8. Brink
    Brink New Member

    Windows Defender Offline Scan in Windows 10

    It appears that the C:\ProgramData\Microsoft\Windows Defender\Offline Scanner folder isn't available by default until you have done an offline scan with Windows Defender Offline first.
     
    Brink, Feb 27, 2016
    #8
  9. Cliff S New Member
    I was trying to see if one of .exe(both as normal and as admin run) would start the offline scan, so you could make a shortcut, but... nope.

    So you think it(like many Windows features) unpacks and installs itself when run for the first time? Makes sense, that would save disk space, if never needed, and resources.
     
    Cliff S, Feb 27, 2016
    #9
  10. Brink
    Brink New Member
    That seems to be the case for this to not be available until used.

    There doesn't appear to be an easy way to create a quick shortcut to directly run this so far. *Sad
     
    Brink, Feb 27, 2016
    #10
  11. Cliff S New Member
    Nope. I have used my MFT scanner(just installed it in the VM) and it cannot find a link to the button, just to the settings. Also it's not in the system32 part of Defender or in Program Files or Program Files(x86) or in the Uni Apps shortcuts list. Maybe if I set File Explorer to Unhide protected OS files?
     
    Cliff S, Feb 27, 2016
    #11
  12. Brink
    Brink New Member
    The tutorial has been updated to add OPTION ONE and OPTION TWO to be able to run a Windows Defender Offline scan using PowerShell and command prompt. *Smile
     
    Brink, Feb 29, 2016
    #12
  13. Cliff S New Member

    Windows Defender Offline Scan in Windows 10

    Now everyone on 1511 and upwards can offline scan now*Thumbs
     
    Cliff S, Feb 29, 2016
    #13
  14. So, I've tried this out on a fully patched 1511 (10586) build of enterprise, and neither of the commandlines (powershell called and cmd called) and neither seem to do anything, the command runs without error, but the scan does not begin. I do have the folder in programdata. Anyone have any thoughts on that?
     
    cubspsycho85, Mar 17, 2016
    #14
  15. Cliff S New Member
    Cliff S, Mar 17, 2016
    #15
Thema:

Windows Defender Offline Scan in Windows 10

Loading...
  1. Windows Defender Offline Scan in Windows 10 - Similar Threads - Defender Offline Scan

  2. Windows defender offline scan not scanning

    in AntiVirus, Firewalls and System Security
    Windows defender offline scan not scanning: The windows defender offline scan is not working. It just shows the blue screen after restarting and that box displaying windows defender offline and that's it. No scan progress is there everytime....
  3. Windows defender offline scan not scanning

    in Windows 10 Gaming
    Windows defender offline scan not scanning: The windows defender offline scan is not working. It just shows the blue screen after restarting and that box displaying windows defender offline and that's it. No scan progress is there everytime....
  4. Windows defender offline scan not scanning

    in Windows 10 Software and Apps
    Windows defender offline scan not scanning: The windows defender offline scan is not working. It just shows the blue screen after restarting and that box displaying windows defender offline and that's it. No scan progress is there everytime....
  5. Windows defender offline scan not scanning

    in Windows 10 Gaming
    Windows defender offline scan not scanning: Whenever I start the defender's offline scan, it will restart my computer then show the blue screen displaying windows offline scan but after this nothing will happen and it will restart again. It will not show any progress of scan. I tried to do it in safe mode but in that...
  6. Windows defender offline scan not scanning

    in Windows 10 Software and Apps
    Windows defender offline scan not scanning: Whenever I start the defender's offline scan, it will restart my computer then show the blue screen displaying windows offline scan but after this nothing will happen and it will restart again. It will not show any progress of scan. I tried to do it in safe mode but in that...
  7. Windows defender offline scan not scanning

    in AntiVirus, Firewalls and System Security
    Windows defender offline scan not scanning: Whenever I start the defender's offline scan, it will restart my computer then show the blue screen displaying windows offline scan but after this nothing will happen and it will restart again. It will not show any progress of scan. I tried to do it in safe mode but in that...
  8. Window defender Offline Scan

    in Windows 10 Installation and Upgrade
    Window defender Offline Scan: I want to do offline scan but my system is asking me for the Bitlocker recovery key of 10th Oct. 2019 whereas the one available in my Ms account is that of 26th Nov. 2018. As a result of this I could not go on with the offline scanning. Please I need help to resolve this...
  9. Windows Defender offline scan

    in AntiVirus, Firewalls and System Security
    Windows Defender offline scan: What's the consensus on the WD offline scan, any good? 124404
  10. Windows Defender Offline Scan

    in Windows 10 BSOD Crashes and Debugging
    Windows Defender Offline Scan: Hello. I have been cleaning my Windows 10 laptop of junk files and decided to do an offline scan. When my laptop restarted, instead of the usual offline scan that I see everytime I do it, I saw a blue screen where a message “Your PC/device needs to be repaired.” I inserted my...

Users found this page by searching for:

  1. windows defender offline scan is it any good

    ,
  2. offline scan is disabled