System File Check, Defender and Windows 10 1903

Discussion in 'other software & services' started by stapp, Jul 10, 2019.

  1. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    24,107
    Location:
    UK
    It doesn't affect my machines that run 3rd party av's.
    Microsoft said...
    https://www.windowslatest.com/2019/...-out-an-update-to-fix-windows-10-sfc-feature/
     
  2. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    Yes, tested again on one (3rd party AV) machine and problem has returned, so persists.

    So likewise - though this was the machine with the WD AV Anti-Malware Platform update KB4052623 to v4.18.1907.4!
     
  3. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Well, Microsoft is wrong since I had the problem using Eset as my real-time AV solution.
     
  4. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,645
    Location:
    USA
    Same here. This was not the case when this issue was first reported.
     
  5. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Also for the life of me, I don't know why this issue is such a big deal.

    It is not affecting any SFC functionality other than it stating it didn't repair all files successfully. A review of the CBS.log would show only the WD PowerShell scripts weren't repaired. I also believe it doesn't affect any WD operational functionality. I suspect those PowerShell scripts are only used by corp. admins for standalone maintenance purposes.
     
  6. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    It's not a big deal, just offends my OCD :D.
     
  7. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,645
    Location:
    USA
    Agreed. :argh:
     
  8. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    I will also add that Microsoft's article is misleading and convoluted as always:
    https://support.microsoft.com/en-au...-flags-windows-defender-ps-files-as-corrupted

    I interpret the above to be both DISM and SFC have to be run after the version 4.8.1908 update of Windows Defender has been applied. As I posted previously yesterday, I received that update after activating WD manually via periodic scan option and then manually forcing an update to it.
     
    Last edited: Aug 19, 2019
  9. plat

    plat Registered Member

    Joined:
    Dec 19, 2018
    Posts:
    2,233
    Location:
    Brooklyn, NY
    For YOU maybe not. As I said, for someone not aware of this, running sfc /scannow and seeing "corrupt" files pertaining to Windows Defender over and over again might provoke actions like a system reset when it's not really necessary. If I didn't know better, and am running Windows Defender as my main antivirus protection, I may not stop and look for issues online; instead, I'd be doing a system reset or something thinking there was something malicious or corrupted going on.

    I just ran sfc again after having restarted the machine a couple of times and it's good (no integrity violations). Again, this update was to come bundled with a definition, oops, security intelligence update or...? Edit: OK, I see where it gets updated, thanks, itman.
     
  10. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Now for the $64,000 question. What about the nob Win user who is clueless as to this issue and what is discussed in this thread?
     
  11. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    164,145
    Location:
    Texas
    If someone is interested in computer security, they will learn like everyone else learns, by doing and reading.
    No one is born with computer knowledge. It is a learned process.
     
  12. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Appears I was specific enough. Microsoft needs to fix their screw-ups without having the user employ DISM and SFC to do so.
     
  13. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Here's an interesting tidbit in regards to this fix. When I checked for example one of the updated scripts, MSFT_MpComputerStatus.cdxml, in its associated C:\Windows\WinSxS directory, it shows a size of 64KB. Let me repeat that .... 64Ko_O. This in contrast to everything else in the directory listed as 1KB. This is a huge size for a PowerShell script. So those that are currently absolutely blocking PowerShell execution and using WD, beware. Also makes me glad I am not using WD.
     
  14. Nightwalker

    Nightwalker Registered Member

    Joined:
    Nov 7, 2008
    Posts:
    1,387
    It wont change anything in his/her life, he/she will continue to do the stuff that he/she wants with reasonably security offered by default via Windows Defender.
     
  15. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    I have a situation (with 3rd party AV, EAM) where I have enabled Periodic scanning, but it seems to toggle off again ...

    But - dumb question - how do I 'force' a WD update. Just check for updates while Periodic scanning option is on?
     
  16. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    24,107
    Location:
    UK
    @paulderdash
    On the machines I have EAM on, I did a Dism/restorehealth and then SFC.
    No corrupt files after that.
     
  17. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    @stapp I did same yesterday, and then later the sfc error came back!

    Could have been something else of course.

    But just checked again, and so far so good.
     
  18. pb1

    pb1 Registered Member

    Joined:
    Apr 4, 2014
    Posts:
    1,278
    Location:
    sweden
    This seems to be a VERY random problem. On a Pro Os, no problem at all.
     
  19. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    Indeed. The Win10 system I had the (repeat) issue on was Pro too.
     
  20. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Might have something to do with EAM usage. Using Eset if I toggle it on, it stays that way. You might have to set an exclusion in EAM for the WD engine .exe. Also is EAM now using the Win 10 ELAM driver? Microsoft in 1903 will load WD at boot time w/realtime scanner active for any AV solution not using the ELAM driver.
    Correct.
     
    Last edited: Aug 20, 2019
  21. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    Weirdly, Periodic scanning option now seems to be staying On (on two EAM machines). I actually do want it On.

    No idea if EAM uses ELAM driver ... googled but not sure, anybody else know? Hmm sorry, getting OT.
     
  22. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,885
    Location:
    Slovenia, EU
  23. Roberteyewhy

    Roberteyewhy Registered Member

    Joined:
    Mar 4, 2007
    Posts:
    611
    Location:
    US
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.