WinDefend Service stopped but spazes out


BrianB

Member
Local time
10:27 AM
Posts
9
OS
Windows 11 23H2
Not sure how to explain this. Installed our VLA image, configured it for our network, meaning firewall off, windows defender off, antispyware off. made an image. Once loaded and on the network, we install Sophos Endpoint XDR. After a restart, anything we do, open file explorer and open a browser, the windefend service wigs out. it starts out stopped, but wigging out I mean it starts/stops/starts/stops hundreds of times while the app is loaded. Once browser is up, it goes back to stopped. But the whole time it does this it really slows down the PC. While it is stopped, the PC is fine, fast as ever.

I have tried to set the services to be disabled, VIA GPO, but it stops SCCM from installing
  1. Use the "Find" feature and locate each folder below and click to change "start" from "3" to "4"
    • Sense
    • WdBoot
    • WdFilter
    • WdNisDrv
    • WdNisSvc
    • WinDefend

and Option 1 in this post

Has anybody seen this?
 
Windows Build/Version
10.0.22621.1413

My Computer

System One

  • OS
    Windows 11 23H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    HPZ2G9
    CPU
    12th Gen i5-12500
    Motherboard
    HP
    Memory
    16gb
    Graphics Card(s)
    Intel UHD 770
    Sound Card
    Realtek High Def
    Monitor(s) Displays
    ViewSonic
    Screen Resolution
    1920x1080
    Hard Drives
    NVMe WD PC SN810 SDCPNRY-512G-1006
    Case
    Pavilion
Looking into this more, I have found that it is the command-line scanner that is spazing out WinDefend service. Although running this "Get-MpComputerStatus" it shows not running
Powershell:
Get-MpComputerStatus


AMEngineVersion                  : 0.0.0.0
AMProductVersion                 : 4.18.2201.11
AMRunningMode                    : Not running
AMServiceEnabled                 : False
AMServiceVersion                 : 0.0.0.0
AntispywareEnabled               : False
AntispywareSignatureAge          : 4294967295
AntispywareSignatureLastUpdated  :
AntispywareSignatureVersion      : 0.0.0.0
AntivirusEnabled                 : False
AntivirusSignatureAge            : 4294967295
AntivirusSignatureLastUpdated    :
AntivirusSignatureVersion        : 0.0.0.0
BehaviorMonitorEnabled           : False
ComputerID                       : 48A8EBC6-D6EF-4EB3-A2CC-639A91C49056
ComputerState                    : 0
DeviceControlDefaultEnforcement  : N/A
DeviceControlPoliciesLastUpdated : 12/31/1600 4:00:00 PM
DeviceControlState               : N/A
FullScanAge                      : 4294967295
FullScanEndTime                  :
FullScanStartTime                :
IoavProtectionEnabled            : False
IsTamperProtected                : False
IsVirtualMachine                 : False
LastFullScanSource               : 0
LastQuickScanSource              : 0
NISEnabled                       : False
NISEngineVersion                 : 0.0.0.0
NISSignatureAge                  : 4294967295
NISSignatureLastUpdated          :
NISSignatureVersion              : 0.0.0.0
OnAccessProtectionEnabled        : False
QuickScanAge                     : 4294967295
QuickScanEndTime                 :
QuickScanStartTime               :
RealTimeProtectionEnabled        : False
RealTimeScanDirection            : 0
TamperProtectionSource           : E3 transition
TDTMode                          : N/A
TDTStatus                        : N/A
TDTTelemetry                     : N/A
PSComputerName                   :
Here is what it does:
 

My Computer

System One

  • OS
    Windows 11 23H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    HPZ2G9
    CPU
    12th Gen i5-12500
    Motherboard
    HP
    Memory
    16gb
    Graphics Card(s)
    Intel UHD 770
    Sound Card
    Realtek High Def
    Monitor(s) Displays
    ViewSonic
    Screen Resolution
    1920x1080
    Hard Drives
    NVMe WD PC SN810 SDCPNRY-512G-1006
    Case
    Pavilion

Latest Tutorials

Back
Top Bottom