Skip to content

Commit 51ca29b

Browse files
committed
added a screenshot and self review
1 parent fb5b679 commit 51ca29b

File tree

2 files changed

+22
-22
lines changed

2 files changed

+22
-22
lines changed
259 KB
Loading

defender-endpoint/troubleshoot-service-startup-problems.md

Lines changed: 22 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
---
22
title: Troubleshoot Microsoft Defender Antivirus service startup problems
3-
description: Find out where settings for Microsoft Defender Antivirus are coming from.
3+
description: Learn how to troubleshoot Microsoft Defender Antivirus service startup problems.
44
author: denisebmsft
55
ms.author: deniseb
66
manager: deniseb
@@ -17,61 +17,59 @@ f1.keywords: NOCSH
1717
audience: ITPro
1818
---
1919

20-
## Troubleshoot Microsoft Defender Antivirus service startup problems   
20+
# Troubleshoot Microsoft Defender Antivirus service startup problems   
2121

2222
**Applies to:**
2323

2424
- [Microsoft Defender XDR](/defender-xdr)
2525

26-
- [Microsoft Defender for Endpoint Plan 1 and 2](microsoft-defender-endpoint)
26+
- [Microsoft Defender for Endpoint Plan 1 and 2](microsoft-defender-endpoint.md)
2727

2828
- [Microsoft Defender for Business](https://www.microsoft.com/security/business/endpoint-security/microsoft-defender-business)
2929

3030
- [Microsoft Defender for Individuals](https://www.microsoft.com/microsoft-365/microsoft-defender-for-individuals)
3131

3232
- Microsoft Defender Antivirus
3333

34-
You may notice that **Virus & threat protection** has a red cross, where it says **Threat service has stopped.  Restart it now**.
34+
In the following screenshot, you can see that **Virus & threat protection** has a red cross, where it says **Threat service has stopped.  Restart it now**.
3535

3636
:::image type="content" source="media/virus-threat-protection.jpg" alt-text="Screenshot of virus and threat protection notification." lightbox="media/virus-threat-protection.jpg":::
3737

38-
Within **Security Providers**, you may see the following:
38+
Within **Security Providers**, you can see the following. <br> You can see that **Microsoft Defender Antivirus is turned off**.
3939

4040
:::image type="content" source="media/security-providers.png" alt-text="Screenshot of security providers." lightbox="media/security-providers.png":::
4141

42-
You can see that **Microsoft Defender Antivirus is turned off.**
42+
In the following screenshot, you can see the message: **Threat service has stopped. Restart it now.**
4343

4444
:::image type="content" source="media/virus-threat-protection-2.png" alt-text="Screenshot of threat service has stopped." lightbox="media/virus-threat-protection-2.png":::
4545

46-
See the message: **Threat service has stopped. Restart it now.**
46+
In the following screenshot, you can see the message: **Unexpected error. Sorry, we ran into a problem. Please try again.** <br> Click **Close**.
4747

4848
:::image type="content" source="media/unexpected-error.png" alt-text="Screenshot of unexpected error." lightbox="media/unexpected-error.png":::
4949

50-
You can see the message: **Unexpected error. Sorry, we ran into a problem. Please try again.** <br> Click **Close**.
51-
52-
### Events
50+
## Events
5351

5452
You may see the following events in the *Windows Defender – Operational* event log:
5553

56-
#### Event 5007
54+
### Event 5007
5755

5856
Microsoft Defender Antivirus Configuration has changed. If this is an expected event you should review the settings as this may be the result of malware.
5957

6058
|Old value |New value |
6159
|---------|---------|
62-
|`HKLM\SOFTWARE\Microsoft\Windows Defender\Diagnostics\RolledbackPlatformHealthData = <OVERALL>:<BAD>,<AGE>:<36>,<DIRTY_SHUTDOWNS>:<22>` | `Default\Diagnostics\RolledbackPlatformHealthData = 0` |
60+
|`HKLM\SOFTWARE\Microsoft\Windows Defender\Diagnostics\RolledbackPlatformHealthData = <OVERALL>:<BAD>, <AGE>:<36>, <DIRTY_SHUTDOWNS>:<22>` | `Default\Diagnostics\RolledbackPlatformHealthData = 0` |
6361
|`Default\ServiceStartStates = 0x0` | `HKLM\SOFTWARE\Microsoft\Windows Defender\ServiceStartStates = 0x1` |
6462
|`HKLM\SOFTWARE\Microsoft\Windows Defender\ServiceStartStates = 0x1` | `Default\ServiceStartStates = 0x0` |
6563
|`Default\ProductAppDataPath = C:\ProgramData\Microsoft\Windows Defender` | `HKLM\SOFTWARE\Microsoft\Windows Defender\ProductAppDataPath = C:\ProgramData\Microsft\Windows Defender` |
6664
|`Default\IsServiceRunning = 0x0` | `HKLM\SOFTWARE\Microsoft\Windows Defender\IsServiceRunning = 0x1` |
6765
|`Default\ProductAppDataPath = C:\ProgramData\Microsoft\Windows Defender` | `HKLM\SOFTWARE\Microsoft\Windows Defender\ProductAppDataPath = C:\ProgramData\Microsoft\Windows Defender` |
6866
|`Default\IsServiceRunning = 0x0` |`HKLM\SOFTWARE\Microsoft\Windows Defender\IsServiceRunning = 0x1` |
6967

70-
#### Event 5001
68+
### Event 5001
7169

7270
Microsoft Defender Antivirus Real-time Protection scanning for malware and other potentially unwanted software was disabled.
7371

74-
### Resolution
72+
## Resolution
7573

7674
The following steps will help to resolve the issue:
7775

@@ -86,10 +84,10 @@ gsv WinDefend, WdBoot, WdFilter, WdNisSvc, WdNisDrv, SecurityHealthService, wscs
8684
| --- | --- | --- | --- | --- |
8785
| Windows Security Service | SecurityHealthService | Manual | Running | |
8886
| Microsoft Defender Antivirus Boot Driver | WdBoot | Boot | Stopped | It’s normal to be stopped after boot. |
89-
| Microsoft Defender Antivirus Mini-Filter Driver | WdFilter | Boot | Running | If stopped, please check steps 3, 6, 7. |
90-
| Microsoft Defender Antivirus Network Inspection System Driver | WdNisDrv | Manual | Running | If stopped, please check steps 3, 6, 7. |
91-
| Microsoft Defender Antivirus Network Inspection Service | WdNisSvc | Manual | Running | If stopped, please check steps 3, 6, 7. |
92-
| Microsoft Defender Antivirus Service | WinDefend | Automatic | Running | If stopped, please check steps 3, 6, 7. |
87+
| Microsoft Defender Antivirus Mini-Filter Driver | WdFilter | Boot | Running | If stopped, check steps 3, 6, 7. |
88+
| Microsoft Defender Antivirus Network Inspection System Driver | WdNisDrv | Manual | Running | If stopped, check steps 3, 6, 7. |
89+
| Microsoft Defender Antivirus Network Inspection Service | WdNisSvc | Manual | Running | If stopped, check steps 3, 6, 7. |
90+
| Microsoft Defender Antivirus Service | WinDefend | Automatic | Running | If stopped, check steps 3, 6, 7. |
9391
| wscsvc | Security Center | Automatic | Running | |
9492

9593
2. Download and run the [Microsoft Safety Scanner](safety-scanner-download.md) to try ruling out any malware.
@@ -112,7 +110,7 @@ gsv WinDefend, WdBoot, WdFilter, WdNisSvc, WdNisDrv, SecurityHealthService, wscs
112110
& "${env:ProgramFiles}\Windows Defender\MpCmdRun.exe" -ResetPlatform
113111
```
114112
115-
6. Backup Microsoft Defender Antivirus policies
113+
6. Backup Microsoft Defender Antivirus policies.
116114
117115
Run the following PowerShell command as an administrator.
118116
@@ -121,7 +119,7 @@ gsv WinDefend, WdBoot, WdFilter, WdNisSvc, WdNisDrv, SecurityHealthService, wscs
121119
Invoke-Command {reg export 'HKLM\SOFTWARE\Policies\Microsoft\Windows Defender' C:\Temp\MDAV\_backup.reg
122120
```
123121
124-
7. Delete any policies that might have been set for Microsoft Defender Antivirus.
122+
7. Delete any policies that are set for Microsoft Defender Antivirus.
125123
126124
Run the following PowerShell command as an administrator.
127125
@@ -130,15 +128,15 @@ gsv WinDefend, WdBoot, WdFilter, WdNisSvc, WdNisDrv, SecurityHealthService, wscs
130128
```
131129
For more information, see: [Troubleshoot Microsoft Defender Antivirus settings](troubleshoot-settings.md).
132130
133-
8. Re-enable Microsoft Defender Antivirus
131+
8. Re-enable Microsoft Defender Antivirus.
134132
135133
Run the following PowerShell command as an administrator.
136134
137135
```powershell
138136
& "${env:ProgramFiles}\Windows Defender\MpCmdRun.exe" -WdEnable
139137
```
140138
141-
9. Update Security Intelligence
139+
9. Update Security Intelligence.
142140
143141
Run the following PowerShell command as an administrator.
144142
@@ -148,4 +146,6 @@ gsv WinDefend, WdBoot, WdFilter, WdNisSvc, WdNisDrv, SecurityHealthService, wscs
148146
149147
10. Make sure that **Tamper Protection** is enabled.
150148
149+
:::image type="content" source="media/tamper-protection.png" alt-text="Screenshot of Tamper Protection is enabled." lightbox="media/tamper-protection.png":::
150+
151151
11. Run **Microsoft Update**.

0 commit comments

Comments
 (0)