{"id":14131,"date":"2020-04-17T00:52:25","date_gmt":"2020-04-16T22:52:25","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=14131"},"modified":"2020-04-17T08:40:40","modified_gmt":"2020-04-17T06:40:40","slug":"scep-mse-defender-broken-signatureupdate-kills-microsoft-antivirus-04-16-2020","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2020\/04\/17\/scep-mse-defender-broken-signatureupdate-kills-microsoft-antivirus-04-16-2020\/","title":{"rendered":"SCEP\/MSE\/Defender: Broken Signatureupdate kills Microsoft Antivirus (04\/16\/2020)"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline;\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2015\/01\/Schutz.jpg\" width=\"40\" height=\"47\" align=\"left\" \/>[<a href=\"https:\/\/www.borncity.com\/blog\/2020\/04\/17\/scep-mse-defender-weltweiter-ausfall-von-microsofts-virenschutz-durch-signatur-1-313-1638-0-16-4-2020\/\" target=\"_blank\" rel=\"noopener noreferrer\">German<\/a>]An update, which may contain a broken signature file, has bricked all Microsoft virus scanners (Windows Defender, Microsoft Security Essential, and System Center Endpoint Protection (SCEP)) since April 16, 2020. The service for performing the virus scan simply crashes. A new signature file with a fix has been released.<\/p>\n<p><!--more--><\/p>\n<h2>All Microsoft Antivirus scan engines bricked<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vg08.met.vgwort.de\/na\/8659a11c1e4b4b3bad79afcb37f2cfc3\" alt=\"\" width=\"1\" height=\"1\" \/>The problem described one year ago in the blog post <a href=\"https:\/\/borncity.com\/win\/2019\/03\/20\/scep-mse-defender-failed-worldwide-for-hours-due-to-a-bad-signatur-file-v1-289-1521-0-03-19-2019\/\">SCEP\/MSE\/Defender failed worldwide for hours due to a bad signatur file v1.289.1521.0 (03\/19\/2019)<\/a>,\u00a0 that a signature update bricked all Microsoft virus scanners, is back since April 16, 2020. I've been contacted an April 16, 2020 at 09:17 a.m. (CET) by German blog reader Michael, reporting issues with System Center Endpoint Protection (SCEP):<\/p>\n<blockquote><p>Good morning.<br \/>\nMS has just distributed (08:39 in our case) updates for SCEP.<br \/>\nHere is an update : KB2461484 (Version 1.313.1638.0)<br \/>\nAs soon as a scan of any action is executed the Endpoint Protection crashes.<\/p><\/blockquote>\n<p>At that time I couldn't find other hits searching the Internet. Shortly after, Michael told me, that he has 400 systems with SCEP, that was affected. Later I received two comments to my blog post <a href=\"https:\/\/borncity.com\/win\/2019\/03\/20\/scep-mse-defender-failed-worldwide-for-hours-due-to-a-bad-signatur-file-v1-289-1521-0-03-19-2019\/\">SCEP\/MSE\/Defender failed worldwide for hours due to a bad signatur file v1.289.1521.0 (03\/19\/2019)<\/a>, reporting the same issues for Windows Server 2012 R2 and Windows 7.<\/p>\n<h3>Windows Defender and MSE also affected<\/h3>\n<p>At the same time I received a similar <a href=\"https:\/\/www.borncity.com\/blog\/2020\/04\/15\/microsoft-security-update-summary-14-april-2020\/#comment-88170\" target=\"_blank\" rel=\"noopener noreferrer\">comment<\/a> from German blog reader Dekre, reporting, that Windows Defender stalls under Windows 10 Version 1909. Dekre reportet the following versions that causes issues:<\/p>\n<p>Antimalware version: 4.18.2003.8<br \/>\nModule: 1.1.6900.4<br \/>\nAV-Version: 1.313.1666.0<br \/>\nAntispyware-Version 1.313.1666.0<\/p>\n<p>Dekre pointet also to the German Microsoft Answers forum with <a href=\"https:\/\/answers.microsoft.com\/de-de\/protect\/forum\/all\/windows-defender-antivirus-startet-nicht\/06c96d63-0927-4b48-9c90-fea5d8e5693e?auth=1\">this thread<\/a> dealing with the same effect. A user wrote:<\/p>\n<blockquote><p>Windows Defender Antivirus does not start<\/p>\n<p>Hello, when I start my PC, the message always comes: \"The virus protection is disabled. Tap or click here to turn on Windows Defender Antivirus.\"<\/p>\n<p>When I click on it, it says: \"Page not available. Your administrator has restricted access to some areas of this app. The resource you're trying to access is unavailable. Contact the helpdesk for more information:\"<\/p><\/blockquote>\n<p>It is specified that the Security Intelligence Update for Windows Defender Antivirus &#8211; KB2267602 (version 1.313.1594.0) contains the error 0x80070643.<\/p>\n<p><img decoding=\"async\" title=\"Defender-Dienst beendet\" src=\"https:\/\/i.imgur.com\/84Wz3PG.jpg\" alt=\"Defender-Dienst beendet\" \/><\/p>\n<p>Within <a href=\"https:\/\/www.borncity.com\/blog\/2020\/04\/16\/april-2020-patchday-nachlese\/#comment-88174\" target=\"_blank\" rel=\"noopener noreferrer\">this comment<\/a> another German blog reader reported issues with a stalling Defender service (see the German screenshot above). Other readers has contacted my via e-mail reporting the same, and the editors of German IT site heise has send me similar reader feedback.<\/p>\n<p>I just checked the Microsoft Security Essentials (MSE) on my Windows 7. The MSE reported that the last scan was a long time ago. When I started a quick scan, everything looked fine. But a short time later I got the following message that the service was stopped.<\/p>\n<p><img decoding=\"async\" title=\"Microsoft Security Essential: Dienstabsturz\" src=\"https:\/\/i.imgur.com\/OAtKVnm.jpg\" alt=\"Microsoft Security Essential: Dienstabsturz\" \/><\/p>\n<p>And next to the notification area of the taskbar the following toast notification of the MSE was displayed.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/i.imgur.com\/YCMAzlQ.jpg\" \/><\/p>\n<p>The virus protection of the Microsoft Security Essentials (MSE) are therefore also completely paralysed. In the meantime, I have also read such a message <a href=\"https:\/\/www.askwoody.com\/2020\/reports-of-windows-security-nee-microsoft-security-essentials-crashing-after-installing-this-mornings-definition-updates\/\" target=\"_blank\" rel=\"noopener noreferrer\">at askwoody.com<\/a>.<\/p>\n<h2>A Fix for the issue<\/h2>\n<p>The reason for the scan engine crashes is a bug that takes effect when a file has two dots before the file name extension (e.g. Test..exe, see also <a href=\"https:\/\/www.reddit.com\/r\/Windows10\/comments\/g29z46\/windows_defender_now_longer_working_after\/fnku3cq\/\" target=\"_blank\" rel=\"noopener noreferrer\">this reddit.com thread<\/a>). Lawrence Abrams did an analysis at Bleeping Computer in <a href=\"https:\/\/www.bleepingcomputer.com\/news\/microsoft\/windows-defender-broken-by-recent-updates-how-to-fix\/\" target=\"_blank\" rel=\"noopener noreferrer\">this article<\/a>. My German MVP colleague Ingo B\u00f6ttcher has written <a href=\"https:\/\/answers.microsoft.com\/de-de\/protect\/forum\/all\/windows-defender-startet-nicht-bzw-der-dienst\/843ebe20-f70b-417c-8493-818ebfdd2847\" target=\"_blank\" rel=\"noopener noreferrer\">this forum post<\/a> in Microsoft Answers:<\/p>\n<blockquote><p>The problem was fixed with the signature update 1.313.1687.0. Via Windows Update or the update search of Defender itself this signature version is distributed since tonight.<\/p><\/blockquote>\n<p>You can manually check for updates. In Windows 10, open the <em>Windows Security<\/em> window, go to <em>Virus &amp; threat protection<\/em> and select the <em>Check for Updates <\/em>hyperlink under <em>Virus &amp; Threat Protection Updates<\/em>. Then the new signature file should be installed by update. For MSE, you should have Windows Update check for updates. After a long search I was offered update KB2310138 with the above signature. After installing this update the error in the MSE seems to be fixed.<\/p>\n<p><strong>Addendum: <\/strong>On April 17, 2020, Microsoft published <a href=\"https:\/\/www.microsoft.com\/en-us\/wdsi\/definitions\/antimalware-definition-release-notes\" target=\"_blank\" rel=\"noopener noreferrer\">another signature update<\/a> to version 1.313.1721.0. My editor from news magazine heise told me that everything is working again on her Windows 10 computer. Interesting observation from her was that the above approach via the Security Center did not work for her because the hyperlink <em>Check for Updates<\/em> was missing. The reason might be that the threat protection service could not be restarted on her computer. She then manually triggered the Windows Update search, which resulted in the signature update. Even without a subsequent restart, the threat protection service was then up and running again.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]An update, which may contain a broken signature file, has bricked all Microsoft virus scanners (Windows Defender, Microsoft Security Essential, and System Center Endpoint Protection (SCEP)) since April 16, 2020. The service for performing the virus scan simply crashes. A &hellip; <a href=\"https:\/\/borncity.com\/win\/2020\/04\/17\/scep-mse-defender-broken-signatureupdate-kills-microsoft-antivirus-04-16-2020\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[463,580,2],"tags":[646,773,47,2393,194],"class_list":["post-14131","post","type-post","status-publish","format-standard","hentry","category-issue","category-security","category-windows","tag-antivirus","tag-defender","tag-issue","tag-scep","tag-windows"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/14131","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=14131"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/14131\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=14131"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=14131"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=14131"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}