none
Microsoft Defender Threat Service has stopped [SOLVED]

    Question

  • https://social.technet.microsoft.com/Forums/getfile/1074583

    https://social.technet.microsoft.com/Forums/getfile/1074584

    PLEASE HELP ME

    I am showing the shield icon with a red X on it.  When I open Windows Defender Security Center it says that the Threat Service has stopped.  Restart it now.  When I click 'Restart Now' it does nothing.  If I choose the shield icon out of the list on the left side of the screen and click on the virus and protection settings next to the gears it shows real time protection is off.
    When I click it to 'on' User Account Control pops up and I choose Yes, then it goes back to the screen but stays on off.
    I'm not sure what it causing it or how to get rid of it either.



    • Edited by James Buenafe Tuesday, May 30, 2017 12:35 PM solved already
    Thursday, May 18, 2017 2:00 PM

Answers

  • I found the solution in my case. THANK GOD! i just put 0 value in Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender

    and poof! there is it I can run my windows defender again!. There is 1 value when I saw it then when I turn it to 0 its okay again!. YAY!

    UPDATE: @everyone Thanks and Welcome for those people I helped with this issue :)
    • Marked as answer by James Buenafe Tuesday, May 30, 2017 12:35 PM
    • Edited by James Buenafe Friday, May 18, 2018 2:19 PM update and welcome
    Tuesday, May 30, 2017 12:26 PM

All replies

  • Hi James, 

    For the service issue, we can use following commands to scan for repairing:

    Please run CMD as administrator and type these commands one by one: 

    Dism /Online /Cleanup-Image /RestoreHealth
    SFC /scannow

    If this issue still persists, please upload the screenshot of the error message and the CBS.log onto OneDrive and share the link here for our research. 


    Please remember to mark the replies as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Monday, May 22, 2017 9:45 AM
    Moderator
  • Hi James, 

    For the service issue, we can use following commands to scan for repairing:

    Please run CMD as administrator and type these commands one by one: 

    Dism /Online /Cleanup-Image /RestoreHealth
    SFC /scannow

    If this issue still persists, please upload the screenshot of the error message and the CBS.log onto OneDrive and share the link here for our research. 


    Please remember to mark the replies as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    I've tried it and here's the result. I'm not sure but I also Dism /Online /Cleanup-Image /CheckHealth.

    Can you please tell me whats wrong with my laptop, and I've upload the Windows Defender error when I want to Update it.

    https://1drv.ms/f/s!Amb63hhXRNXfeY0cjNa8OCm_EMI

    Friday, May 26, 2017 2:47 PM
  • Hi James, 

    For the service issue, we can use following commands to scan for repairing:

    Please run CMD as administrator and type these commands one by one: 

    Dism /Online /Cleanup-Image /RestoreHealth
    SFC /scannow

    If this issue still persists, please upload the screenshot of the error message and the CBS.log onto OneDrive and share the link here for our research. 


    Please remember to mark the replies as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    I followed the steps quoted, however it had no effect on the issue.

    I found that other previously installed software (i.e. Spybot Search & Destroy) was causing the issues. When Spybot S&D was uninstalled, the Microsoft Defender Threat Service has started to work as expected.

    Monday, May 29, 2017 11:50 PM
  • Glad to hear that your issue has been resolved, you are right that 3rd party applications sometimes cause the system service issue.

    Please remember to mark the replies as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Tuesday, May 30, 2017 7:40 AM
    Moderator
  • I found the solution in my case. THANK GOD! i just put 0 value in Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender

    and poof! there is it I can run my windows defender again!. There is 1 value when I saw it then when I turn it to 0 its okay again!. YAY!

    UPDATE: @everyone Thanks and Welcome for those people I helped with this issue :)
    • Marked as answer by James Buenafe Tuesday, May 30, 2017 12:35 PM
    • Edited by James Buenafe Friday, May 18, 2018 2:19 PM update and welcome
    Tuesday, May 30, 2017 12:26 PM
  • Great! it works and solved ,,,much appreciated. 
    Tuesday, July 18, 2017 3:52 AM
  • And it actually worked!!Wow.First time has a comment helped me from hundreds I have seen earlier.THANKS BRO

    Friday, August 4, 2017 1:19 PM
  • This made me feel like a grand ole techie just like back in the day.  Catch up with you, nice too, sir.
    Saturday, August 5, 2017 7:02 PM
  • Thank you so much buddy. It worked...
    Sunday, August 13, 2017 12:00 PM
  • thank you so much sir!
    Thursday, August 17, 2017 2:11 PM
  • thanks! worked!

    Tuesday, September 5, 2017 10:36 PM
  • thanks man. you saved me

    Sunday, September 17, 2017 8:29 AM
  • Thanks! This worked for me as well!

    Tuesday, October 17, 2017 4:36 PM
  • This worked for me as well!

    Tuesday, October 17, 2017 4:37 PM
  • Thank you, James that was the fix for mine as well. Can't tell you how thankful I am.
    Monday, October 23, 2017 4:23 PM
  • You sir just made my day! Not sure why/how did this happen? Anyways, thanks a lot!
    Thursday, November 2, 2017 9:20 AM
  • After you click "Restart Now" you were probably wanting something to happen right away.  You have to have patience and wait a few seconds longer then should connect to change red X to a green check and you're good to go.
    Friday, November 10, 2017 4:18 PM
  • This worked for me as well, Thanks!
    Saturday, November 11, 2017 5:38 AM
  • That Works. Thanks
    Saturday, November 18, 2017 10:09 PM
  • OMG THANK YOU SO SO SO SO MUCH!!!!

    This worked PERFECT. 

    I installed AVG and it was a VIRUS called Heartless and made it seem like it was installing with a 15 second gap in between so if u click again thinking its not loading it made another one. So I figured out how to Get rid of it and the FOLDER I FOUND FOR IT was called HUMOR. Im not going to LIE, It was FUNNY at FIRST until I killed my WINDOWS STUFF. Now I need to see if I can UPDATE. That was messed up to. 

    THANKS AGAIN. Email me j-sinn@hotmail.com if you have a GOOD CLEAN COPY of a DECENT SPYWARE PROGRAM. I REALLY LIKE AVG TUNE UP but I cant seem to find one and the Trail Version says its deleting stuff of your PC but its really NOT. Unless u have it Registered and the KEYS NEVER WORK.

    THANKS AGAIN

    Thursday, November 23, 2017 6:10 PM
  • I bow before your excellence! First a little background(babbling)! I had been using another anti-virus program and had disabled the threat protection of Windows Defender.  Ended getting nailed by a nasty virus from what was supposed to be a legitimate free media player program, I had downloaded a couple of other programs from the site and had no problem with them.  Apparently someone uploaded this program that contained a NASTY that my ant-virus program did not detect.  Whomever created that THING new what they were doing.  It inserted several things into my system and wreaked havoc.  Thankfully several "special" anti-malware programs were able to remove the infection(s), ESET(sorry Winfolk) online scanner was great help.  Unfortunately, some files and registry entries sustained a little damage.  Most of it I was able to get repaired except the Win10 start menu was toast.  Every fix I tried was a fail.  Ended up trying an experiment with a little program that changed the Win10 start menu to Classic Menu,  I chose the Win7 style with a few alterations and voila, I had a start menu again.  I run Win7 on my other laptop, always did like Win7, so I'm fine with that menu!!!

    I uninstalled everything but Windows Defender but was unable to get the threat protection restarted.  Did a search and one of the suggestions was this page(first one I looked at) the registry fix was the answer.  Most excellent!  BTW, I tried the  Dism /Online /Cleanup-Image /RestoreHealthSFC /scannow  and it came up as everything peachy, actually ran it in my attempts to fix the start menu.  I also uninstalled Spybot Search&Destroy before attempting to restart the Windows Defender Threat service and any other programs I had used.

    Your Registry fix was what worked, a 1 to a 0,  yeesh, how simple, I'm laughing my tail off at how easy it was to fix!

    Thank you very, very much!

    Bill Teller

    Tuesday, November 28, 2017 4:47 AM
  • Hi James and all those that have contributed here.

    I have been reading and applying the solutions listed in this forum with interest, as I too am experiencing this problem. However both solutions suggested I have tried and they have failed to make any difference. This could have a lot to do with the registry file you mentioned not existing in my case. In other words I can't alter the value of that registry file, as that registry file doesn't seem to exist.

    The Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender exist and there is the first file under that URL, but no second file can be seen.

    Any suggestions on how to solve this issue in my unique case would be very much appreciated.

    I also tried:

    Please run CMD as administrator and type these commands one by one: 

    Dism /Online /Cleanup-Image /RestoreHealth
    SFC /scannow

    The search results were "Windows Resource Protection did not find any integrity violations."

    Wednesday, December 20, 2017 12:18 AM
  • same problem

    Monday, December 25, 2017 9:08 AM
  • This worked for me. What is odd is was the latest "service pack" for windows 10 that did this!!! I absolutely cannot stand windows 10 update!!!!
    Saturday, December 30, 2017 12:19 AM
  • the registry values "Disable..." in "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender" are  not created by a Windows update.
    They were either created manualy, by a 3rd party antivirus, or by malware.
    • Edited by EckiS Saturday, December 30, 2017 9:18 AM
    Saturday, December 30, 2017 9:17 AM
  • tnx for this guide ^_^
    Thursday, January 4, 2018 2:28 PM
  • thanks so much. helped alot

    Tuesday, January 9, 2018 1:49 PM
  • Thanks.... it worked.
    Wednesday, January 17, 2018 4:32 AM
  • Hi

    it worked for me as well !

    Thank you so much :)

    Wednesday, January 17, 2018 6:20 AM
  • Praise be to the almighty computer gods, this gremlin has been slayed....
    Wednesday, January 17, 2018 6:25 PM
  • Perfectly working

    Tuesday, January 23, 2018 7:15 PM
  • Thanks, it's working for me.  :)
    Thursday, January 25, 2018 4:32 AM
  • Thanks Buddy.

    Friday, January 26, 2018 4:14 AM
  • This is an easy answer. It saved my time.
    Friday, February 2, 2018 11:58 AM
  • Worked for me too - thanks!

    This was driving me nuts for weeks.


    jt

    Saturday, February 3, 2018 4:55 PM
  • it works

    thx buddy

    Tuesday, February 6, 2018 12:39 PM
  • Thanks!! It really worked!!!
    Thursday, February 8, 2018 9:11 AM
  • worked for me too, cheers
    Thursday, February 8, 2018 6:25 PM
  • it doesn't solve issue permanently when i restart my computer than again it showing same problem
    Sunday, February 18, 2018 5:38 AM
  • Worked, thanks

    Happened after a w10 update to version 1709.


    Sunday, February 18, 2018 10:12 PM
  • woooow.... it worked for me. the defender is up and running again. thanks guys!
    Thursday, February 22, 2018 12:07 AM
  • Wow! Man this thing drove me crazy bit you did it!!! Thank you so much.!

    James Pearson

    IT WORKED!!!!!

    Thursday, February 22, 2018 11:24 PM
  • hi james, how if the screen said can not be modify ???

    Saturday, February 24, 2018 6:06 PM
  • THANK YOU !! I did what you said and it worked :D
    Monday, February 26, 2018 6:56 PM
  • tky it worked
    Wednesday, February 28, 2018 10:30 AM
  • Worked, thanks
    Tuesday, March 6, 2018 3:42 AM
  • thanks man
    Saturday, March 10, 2018 5:12 AM
  • You are correct.  Also the original poster forgot to caution messing with the registry can be a very dangerous thing.  Change things at your own risk!  The value was put there by design form Microsoft for a reason or by a third party or virus or intentional.  Changing registry values my cause unintended affects.  so while it may work, know the consequences.
    Friday, March 16, 2018 1:40 PM
  • thanks a lot

    Friday, March 23, 2018 2:21 AM
  • Thank you so much. It works for me.

    Wednesday, April 11, 2018 3:07 PM
  • Thanks James. Mine had "value not set" so I set value at 0 and it now works OK. Don
    • Proposed as answer by applehigh Thursday, April 12, 2018 7:47 PM
    Thursday, April 12, 2018 7:41 PM
  • thanks! It solved my problem too..

    Sunday, April 15, 2018 9:03 AM
  • awesome man, u're a life saviour!!
    Friday, April 20, 2018 3:48 PM
  • This worked for me.

    Thank you.

    Saturday, May 5, 2018 1:09 AM
  • Open RegEdit
    Go to: Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender
    CREATE a key:
    Right-click - New DWord
    Name it: DisableAntiSpyware
    Set value to 0

    *The KEY did NOT exist.

    (Missing step is CREATE KEY called DisableAntiSpyware if it does not already exist, and set value to 0)
    Thursday, May 17, 2018 6:48 PM
  • @TerryDillon: you are confusing key and value.
    Windows reads a value of type DWORD named DisableAntiSpyware under the key "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender"

    but when this is not existing, the default is 0.
    So I wonder what you are trying to achieve?
    Thursday, May 17, 2018 7:00 PM
  • Worked! Thanks so much!
    Wednesday, May 23, 2018 2:24 AM
  • Thanks a lot, worked like a charm. 
    Wednesday, May 30, 2018 2:44 AM
  • Hi James,

    I have run RestoreHealth and got "The operation completed successfully"

    But when I run scannow I got the following msg

    C:\WINDOWS\system32>SFC /scannow
    Beginning system scan.  This process will take some time.
    Beginning verification phase of system scan.
    Verification 100% complete.
    Windows Resource Protection found corrupt files but was unable to fix some of them.
    For online repairs, details are included in the CBS log file located at
    windir\Logs\CBS\CBS.log. For example C:\Windows\Logs\CBS\CBS.log. For offline
    repairs, details are included in the log file provided by the /OFFLOGFILE flag.

    The system file repair changes will take effect after the next reboot.

    For your info, I have checked the value in (in Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender) it is already 0

    I couldn't start the service

    Monday, June 4, 2018 11:56 PM
  • I have the same issue.  SFC scan shows no corruption.  I had Avira installed, but have completely removed it.  I want to know the dependencies of the Virus & Threat Protection service as it will start but then stop after a few seconds.  I had Avira installed as this was happening after the big Windows update.  I completely deleted the registry key for Disable Antivirus to see if some other code was rewriting it- and nothing appears after reboot.  I'm stumped.  It keeps happening to me.
    Saturday, June 30, 2018 5:07 PM
  • I have the same issue.  SFC scan shows no corruption.  I had Avira installed, but have completely removed it.  I want to know the dependencies of the Virus & Threat Protection service as it will start but then stop after a few seconds.  I had Avira installed as this was happening after the big Windows update.  I completely deleted the registry key for Disable Antivirus to see if some other code was rewriting it- and nothing appears after reboot.  I'm stumped.  It keeps happening to me.

    Fixed it.  Used elevated PowerShell and added regkey manually after I deleted it.  Now the service stays active.  **** This will force a reboot of your system so close all your apps etc and just leave PowerShell open ****

    Set-ItemProperty 'HKLM:\SOFTWARE\Policies\Microsoft\Windows Defender' DisableAntiSpyware 0
    Restart-Computer

    Stay Frosty,

    I'm Chappie


    • Edited by I'm Chappie Saturday, June 30, 2018 5:50 PM
    Saturday, June 30, 2018 5:49 PM
  • Hi.

    I have the same issue.

    the diagnostic does not <g class="gr_ gr_71 gr-alert gr_gramm gr_inline_cards gr_run_anim Grammar multiReplace" data-gr-id="71" id="71">shows</g> anything (all good).

    The register fixing neither.

    any other clue ?

    Friday, July 6, 2018 7:04 AM
  • Hi, I tried this but when I saw it the DisableAntiSpyware one wasn't there. But each time I restart the thing, it works. But like 5 seconds like it doesn't work, it just goes back and says restart! Please help me! D:
    Wednesday, August 8, 2018 4:08 AM
  • Fixed it.  Used elevated PowerShell and added regkey manually after I deleted it.  Now the service stays active.  **** This will force a reboot of your system so close all your apps etc and just leave PowerShell open ****

    Set-ItemProperty 'HKLM:\SOFTWARE\Policies\Microsoft\Windows Defender' DisableAntiSpyware 0
    Restart-Computer

    Stay Frosty,

    I'm Chappie


    Thank you for posting this, it solved my problem when nothing else would :)
    Wednesday, October 24, 2018 12:56 PM
  • Likewise to the Post Above by TerryDillon on May 17, 2018

    "Found the above and *needed created a New DWord named DisableAntiSpyware with a value of 0.



    • Edited by pm1_44 Sunday, November 18, 2018 3:19 PM
    Sunday, November 18, 2018 3:17 PM