• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 1136
  • Last Modified:

'Virus scan failed' for all downloads in Chrome, Opera, IE on Windows 8.1

Just yesterday, I began having an issue on my work machine running Windows 8.1 x64 along with Chrome 41 BETA x64, Opera 27, IE 11.0.9600.17631. All download attempts fail with a virus detected warning (varies from browser to browser). The only browser that seems unaffected is Firefox 35.0.1 - the others listed above do not work.

I found a co-worker who has an eerily similar setup to mine. He's unable to recreate this problem. These changes were made to both of our machines yesterday:
February Patch Tuesday updates were applied
Definition update for System Center Endpoint Protection 2012

The other changes that occurred that I did uniquely were:
Ran 'powercfg.exe -h off' to kill the 26GB hiberfile.sys on my SSD
Ran cleanmgr.exe and cleaned user and system files
Ran cleanmgr.exe and removed all but most recent restore point
Ran 'dism /online /image-cleanup /analyzecomponentstore'
Ran 'dism /online /image-cleanup /startcomponentcleanup'
Moved the page file location to data drive

Troubleshooting steps I've taken so far that haven't worked:
I disabled real-time protection in Endpoint Protection
I verified that the Custom Level settings in Internet Options>Security>Internet were set to prompt for downloads
I reset IE as an administrator
I followed the directions located here: http://support.microsoft.com/kb/883260. I created an Attachments subkey in HKCU and set its value to 1.

The only way I've been able to get this to work is by locating that same 'ScanWithAntiVirus' value in HKLM and setting it to 1. Currently, that's what I'm running with and things are downloading as expected. However, I don't think that's a good way to go long term.

I've been a technician for many years and I've never really experienced any of the above things causing something like this. However, something obviously changed as I was downloading files just fine every day before yesterday.

Can anyone offer any insight into this? I would love to know what to do or to learn about some hidden pocket of settings. I don't want to just forfeit and refresh Windows if I don't have to.

Thanks,
Josh
0
price1jj
Asked:
price1jj
  • 4
  • 3
2 Solutions
 
ComputerTechieCommented:
I would try making a usb disk with hitman pro and see what is said. Http://surfright.com

Also what is your antivirus software?

CT
0
 
btanExec ConsultantCommented:
Some changes or services must have meddle with that registry keys. Agree having the setting it to '1' turns the off the function is no long term plan. Setting it to '3' turns it on and is what originally it should be ...thought I wonder if '2' that makes the system run scan loosely can works as well. If it doesnt, likely the scanner (most probably SCEP) is highly suspected for this interfere

I also thinking on multiple scanner as well as normally the value of "3" turns the waits for the first scanner to return an "infected" response to cause the block and any further operation or downloading. The value of "2" allows all the multiple scanners registered in machine to scan before acting on any "infected" results. Wondering it may be possible that there's a latency issue involving the Microsoft Manager and the SCEP hence more time to respond is required after some recent changes in the machine.

Separately, there seem similar forum discussion in which KB3036437 or SCEP (your AV) is the suspected cause. No good conclusion https://social.technet.microsoft.com/Forums/en-US/78d1d963-a74f-4a6f-8ff6-65d0b5a1516a/kb3036437-system-center-endpoint-protection-47-blocks-downloads?forum=FCSNext

but may be worth re-installing SCEP and try again...else try another AV to see if it affects with these KB and updates already installed ...
0
 
price1jjAuthor Commented:
@btan - that TechNet post is actually identical to the problem that I am having. A user mentions a few posts down that FireFox works, but Opera, IE and Chrome do not. I checked my SCEP version and it is, in fact, 4.7.205.0. I also LOVE the fact that this issue appears to be intermittent among machines in our organization.

While I obviously work in IT, and do work in our centralized IT unit, I do want to avoid making changes to my AV configuration to become different from what our users are expected to run. I am going to ask around now and see if any of the technicians are hearing about this from any of their users.

I will be trying the value of 2 to see what it does. Thanks for the suggestion!
0
Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
btanExec ConsultantCommented:
noted thanks for sharing, hopefully we can isolate further to find the root cause and test out the machine even with re-installing the SCEP agent. Steps shared from forum:
Rename the folder C:\ProgramData\Microsoft\Windows Defender to C:\ProgramData\Microsoft\Windows Defender.old   <--- this is the important step, without this the process fails
uninstall System Center Endpoint Protection
Wait for it to be uninstalled
Test that you can download files without issue
Download to the System Center Endpoint Protection installer to their desktop
Install System Center Endpoint Protection
Test your ability to download files.
0
 
price1jjAuthor Commented:
Neither setting it to 2 nor renaming that folder worked. I am going to reinstall later today to determine if that will fix it.

So far, I am not hearing from anyone else in our organization of thousands that this problem exists. Lucky me.
0
 
btanExec ConsultantCommented:
also maybe to check out the EndpointProtectionAgent.log (default inside C:\Windows\CCM\Logs\) to see any other hints to this peculiarity. Also maybe good to see if the policy for one of the working machines and your machine on the applied policy history. E.g. Under the regedit, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CCM\EPAgent\LastAppliedPolicy will have a list of all anti-malware policies along with all merged settings which are shown with a value of “0x00000002”. Or with admin run in cmd, the  reg query HKLM\SOFTWARE\Microsoft\CCM\EPAgent\LastAppliedPolicy /f 2 /d. hopefully we can sieve why so different behaviour, i assuming the browser ver is same
0
 
price1jjAuthor Commented:
I've been unable to recreate this issue on my machine. I changed the registry setting back to scan attachments after this patch window - which was really yesterday for our client machines - and it doesn't seem to be causing any issues anymore. Meanwhile, no one else is really seeing this problem in our organization and they weren't.

I am going to accept a couple solutions... while they aren't exact answers, they definitely either turned me on to ways to narrow it down or even a workaround. I appreciate the help with this... I cannot wait until I have a question for EE that isn't wacky as all heck!

Josh
0
 
btanExec ConsultantCommented:
thanks for sharing
0

Featured Post

When ransomware hits your clients, what do you do?

MSPs: Endpoint security isn’t enough to prevent ransomware.
As the impact and severity of crypto ransomware attacks has grown, Webroot has fought back, not just by building a next-gen endpoint solution capable of preventing ransomware attacks but also by being a thought leader.

  • 4
  • 3
Tackle projects and never again get stuck behind a technical roadblock.
Join Now