Windows Defender Obfuscated Logs

Claire Clough 1 Reputation point
2022-07-19T08:27:00.607+00:00

Is it possible to de-obfuscate / read the following log files?

C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results

\Quick

\Resource

\System

(this applies to both Server 2019 and Windows 10)

I am running into 2 scenarios where Defender is

a) Using a enough CPU on a hyper-v host that it briefly affects the VM performance

b) Locking an entire hard-drive (not OS drive) for an extended period while it reads the entire MFT, we know it is because we caught it in the act doing it sequentially with procmon.

Claire

Windows for business | Windows Client for IT Pros | Storage high availability | Virtualization and Hyper-V
Windows for business | Windows Client for IT Pros | Devices and deployment | Configure application groups
Windows for business | Windows Server | User experience | Other
Windows for business | Windows Server | Devices and deployment | Configure application groups
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Reza-Ameri 17,341 Reputation points Volunteer Moderator
    2022-07-19T15:49:57.28+00:00

    In case you have a performance issue with Microsoft Defender, you have to use New-MpPerformanceRecording to analyze it.
    You may have a look at:
    https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/tune-performance-defender-antivirus
    There is no need review that file.

    0 comments No comments

  2. Limitless Technology 39,926 Reputation points
    2022-07-20T10:02:26.037+00:00

    Hello

    Thank you for your question and reaching out. I can understand you are having query related to Defender logs

    Right-click on the Start button and choose Event Viewer. Then navigate to Applications and Services Logs > Microsoft > Windows > Windows Defender > Operational:

    Logs Locations

    C:\ProgramData\Microsoft\Windows Defender\Support\

    C:\Users\All Users\Microsoft\Windows Defender\Support\

    C:\Windows\Microsoft Antimalware\Support

    C:\ProgramData\Microsoft\Windows Defender\Offline Scanner

    -----------------------------------------------------------------------------------------------------------------------------------

    --If the reply is helpful, please Upvote and Accept as answer--

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.