 |
Welcome to Windows 7 Forums. Our forum is dedicated to helping you find solutions with any problems, errors or issues you are experiencing with Windows 7. The Windows 7 forum also covers news and updates and has an extensive Windows 7 tutorial section that covers a wide range of tips and tricks.
Windows 7 - Windows Defender Offline Windows Defender Offline How to Use Windows Defender Offline
Published by Brink
05-31-2011
| Windows Defender Offline How to Use Windows Defender Offline  Information The former Microsoft Standalone System Sweeper (MSSS) BETA has been rebranded and available as Windows Defender Offline now. Windows Defender Offline is a free standalone, bootable malware and virus remover from Microsoft that performs an offline scan of an infected PC to remove viruses, rootkits and other advanced malware.
This tutorial will show you how to update and use the Windows Defender Offline Tool to create a 32-bit or 64-bit Windows Defender Offline bootable CD/DVD, USB flash drive, or ISO file on any computer to help you start an infected 32-bit or 64-bit PC and perform an offline scan at boot to help identify and remove rootkits and other malicious malware. In addition, Windows Defender Offline can be used if you cannot install or start an antivirus program on your computer, or if the installed AV program can’t detect or remove malware on your computer.
The log files for Windows Defender Offline are stored in a MPLog-MM/DD/YYYY-HH/MM/SS .txt file in the folder below on the computer that was scanned at boot. C:\Windows\Windows Defender Offline\Support For Windows Defender Offline FAQ's, see: Windows Defender Offline: frequently asked questions  Note Minimum System Requirements:- Operating system:
- Windows XP (Service Pack 3)
- Windows Vista (RTM, Service Pack 1, or Service Pack 2, or higher)
- Windows 7 (RTM, Service Pack 1, or higher)
- Required processor:
- Windows XP: 500 MHz or higher: 1.0 GHz or higher
- Windows Vista and Windows 7: 1.0 GHz or higher
- Required memory:
- Windows XP: 768 MB RAM or higher
- Windows Vista and Windows 7: 1 GB RAM or higher
- Required video card: 800 × 600 or higher
- Available hard disk space: 500 MB
- A connection to the internet to be able to update the malware definitions on a created Windows Defender Offline bootable USB flash drive.
- A blank CD, DVD, or a USB flash drive with at least 512 MB of free space. No more than 4GB recommended for the USB flash drive.
The following additional requirements apply only to the computer infected by a virus or malware: - The computer infected with a virus or malware that is being scanned at boot must have the same Windows operating system architecture as the bootable Windows Defender Offline Beta, either 32-bit or 64-bit.
- Internet connection: Only required to update the latest malware definitions for a Windows Defender Offline bootable USB flash drive.
- In addition, BitLocker must be disabled to use Windows Defender Offline Beta.
 Tip If you get a Error Code 0x8004cc04, Error Code 0x8004cc05, or Error Code 0x8050800c while using Windows Defender Offline, then please see the same suggested solutions here for MSSS. STEP ONE
To Create a "Windows Defender Offline" Bootable CD/DVD, USB Flash Drive, or ISO File
1. If you have not already, you will need to download the same 32-bit or 64-bit version of Windows Defender Offline Tool at the download link below for the same 32-bit or 64-bit Windows that is installed on the computer that you will be scanning at boot, and save the exe file to your desktop. 2. Run the downloaded mssstool64.exe (64-bit) or mssstool32.exe (32-bit) file, and click on Next. (see screenshot below) 3. Click on the I accept button. (see screenshot below) NOTE: You will only be prompted for this the first time that you run the Windows Defender Offline Tool. 4. Do step 5, 6, or 7 below for what type of bootable "Windows Defender Offline" CD/DVD, USB, or ISO that you would like to create to scan with. (see screenshot below) 5. To Create a"Windows Defender Offline" Bootable CD or DVDA) Insert a blank unformatted CD or DVD into the CD/DVD drive. NOTE: If a AutoPlay window opens afterwards, close it.
B) Select (dot) Use a blank CD or a DVD, and click on Next. (see screenshot below step 4)
C) If you have more than one DC/DVD drive, then select the CD/DVD drive with the blank CD/DVD in it, and click on Next. (see screenshot below) D) When it's finished, click on Finish. (see screenshot below) NOTE: Be sure to label the CD/DVD as being able to only be used on a 32-bit or 64-bit Windows computer at boot. E) Go to step 8. 6. To Create a "Windows Defender Offline" Bootable USB Flash Drive  Note If you run the Windows Defender Offline Tool again on the same USB flash drive, and if the following conditions below are met, the tool will only download new updated malware definitions (approx. 69.48 MB) and update the USB drive without reformatting it. - The USB flash drive has Windows Defender Offline previously installed on it.
- The Windows Defender Offline Tool version that was used to create the bootable USB flash drive the first run is the same as the one being used for the second run.
- Files on the USB flash drive are not damaged or missing (the tool will verify that).
A) Connect a USB flash drive that is not password protected to your computer. WARNING: This USB drive will be formated during this process, so be sure to backup anything that you do not want to lose to another location first.
B) Select (dot) On a USB flash drive that is not password protected, and click on Next. (see screenshot below step 4)
C) If you have more than one USB drives connected, then select the one that you want to use, and click on Next. (see screenshot below) D) When it's finished, click on Finish. (see screenshot below) E) Go to step 8. 7. To Create a "Windows Defender Offline" Bootable ISO FileA) Select (dot) Create Standalone System Sweeper on an ISO File, and click on Next. (see screenshot below step 4)
B) Select (browse) where you would like to save the ISO file to, and click on Next. (see screenshots below)  C) When it's finished, click on Finish. (see screenshot below) D) You can now use the ISO file to boot with in a virtual machine (ex: Windows Virtual PC), or use the free Windows 7 USB/DVD Download Tool to burn the ISO to a DVD or USB flash drive.
E) Continue on to step 8. 8. You will now be able to boot from the 32-bit or 64-bit CD/DVD, USB, or ISO that you created to run Windows Defender Offline on the same 32-bit or 64-bit computer as in the STEP TWO section below when you like. STEP TWO
To Scan a Computer with the Bootable CD/DVD or USB Flash Drive
1. Insert or connect the same 32-bit or 64-bit Windows Defender Offline bootable CD/DVD or USB flash drive to the same type of 32-bit or 64-bit Windows computer that you want to scan at boot. NOTE: For example, you can only use a created 32-bit USB on a 32-bit computer at boot, and you can only use a created 64-bit USB on a 64-bit computer at boot. 2. In the BIOS or Boot Menu of the computer that you want to scan, be sure that you have it set to boot from the CD/DVD or USB flash drive created in the STEP ONE section above, and boot from it. NOTE: Please consult your computer's or motherboard's manual for exact details on how to do this. 3. This is what you will see while it's booting from the CD/DVD or USB flash drive.  4. When Windows Defender Offline has booted, you will be able to update the definitions and select what type of scan you would like to run on the computer. A Full Scan is recommended, and could take several hours to complete. NOTE: You will only be able to update the definitions at boot if you are using a bootable USB flash drive with a internet connection, and not with a bootable CD/DVD.   5. When finished, close Windows Defender Offline to restart the computer back into Windows. That's it,
Shawn |  Published by | | Administrator Join Date: Oct 2008 Location: Texas Posts: 37,304 | |
 Tutorial Tools | | | | | | | | | |
05-31-2011
|
#1 | | |
Another excellent tutorial, Brink. Thanks.
One question....stated at the bottom of the download page is the message that your computer must be able to run Microsoft Security Essentials. Does this mean that MSE will be installed and will this conflict with Norton 360 version 5 which I currently use? I have always thought that one should never have two AV programmes installed since they may interfere with each other, and Windows doesn't like it.
| My System Specs | | System Manufacturer/Model Number Mesh 955 XGS OS Windows 7 64 bit CPU Athlon X4 955 Black edition Motherboard ASUS M4A78 Pro Memory 8GB DDR2 Graphics Card 1x Radeon 4890 Monitor(s) Displays IIyama ProLite E2208HDS Screen Resolution 1920X1080p Keyboard MS wireless 6000 Mouse MS wireless laser 7000 PSU 600 watt Cooling Standard Hard Drives 2x 1TB Samsung SATA2
1x 320GB IDE Internet Speed Not as fast as it should be...... |
05-31-2011
|
#2 | | Windows 7 Ultimate x64 SP1 |
No, it won't install MSE. | My System Specs | | System Manufacturer/Model Number Airbot 2.0 OS Windows 7 Ultimate x64 SP1 CPU Core i7 920 (D0) @ 4Ghz, *26c idle *65c full load on air Motherboard Asus P6X58D Premium - Sata 6Gb/s - USB 3.0 Memory 12GB DDR3 Corsair Dominator -CMD12GX3M6A1600C8 at 1600MHz Graphics Card EVGA GeForce GTX 480 -Aftermaket Accelero Xtreme Plus cooler Sound Card ASUS Xonar D2X Monitor(s) Displays 1 LG 24" Flatron W2453V-PF 1 Samsung 24" P2450H both 2ms RT Screen Resolution 1920x1080@60hz Keyboard Logitech Wireless MK700 Mouse Logitech Wireless MK700 PSU Corsair HX1000W Case Cooler Master HAF 932 Cooling Case Fans *3 230mm, *1 140mm/CPU - *Tuniq Tower 120 Extreme Hard Drives 1 OCZ Vertex2 180GB SSD
1 TB Samsung Spinpoint F1 7200RPM 32MB cache
2 500GB WD Caviar Blacks 7200RPM 32MB cache (WD5001AALS)
Pioneer DVD Burner DVR-S18M Internet Speed DL 15 Mbps UL 0.98 Mbps Other Info Processor-7.7 *RAM- 7.9 *Graphics-7.9 *Gaming Graphics- 7.9 *SSD- 7.8 W.E.I final score= 7.7
*Phone- Samsung Galaxy Nexus |
05-31-2011
|
#3 | | Windows 7 Ultimate x64 SP1 |

Quote: Originally Posted by beauparc Another excellent tutorial, Brink. Thanks.
One question....stated at the bottom of the download page is the message that your computer must be able to run Microsoft Security Essentials. Does this mean that MSE will be installed and will this conflict with Norton 360 version 5 which I currently use? I have always thought that one should never have two AV programmes installed since they may interfere with each other, and Windows doesn't like it. Hello Steve,
No, Microsoft Security Essentials (MSE) or anything else will not be installed. It was just a reference as an optional separate program that you could install on the computer and use if you did not already have a antivirus program installed on your computer. Microsoft Standalone System Sweeper is a standalone program that runs at boot from the created CD/DVD, USB, or ISO instead, and does not install anything on your computer. | My System Specs | | System Manufacturer/Model Number Self built custom OS Windows 7 Ultimate x64 SP1 CPU Intel i7-980X 3.3 Ghz (3.48 Ghz OC'd) Motherboard ASUS P6X58D Premium Memory 12 GB (2GBx6) DDR3 PC3-16000 2000 MHz Kingston HyperX Graphics Card Sapphire HD5870 Eyefinity 6 2GB Sound Card Realtek HD Audio ALC889 Integrated Chip Monitor(s) Displays 3x 27" Asus VE278Q Screen Resolution 1920x1080 Keyboard Logitech Cordless Desktop MX 5500 Revolution Mouse Logitech Cordless Desktop MX 5500 Revolution PSU OCZ Series Gold OCZZ1000M 1000W Case Corsair Obsidian 800D Cooling Thermalright Ultra 120 Extreme Copper CPU heat sink w/120 MM Hard Drives 160GB OCZ RevoDrive X2
** 2 x 1TB Samsung HDD HD154UI SATA Internet Speed 50 Mb/s Download and 2 Mb/s Upload Other Info Microsoft LifeCam Cinema
** Lite-On iHBS212 12x BD Writer
** Samsung CLX-3175FW Printer
** Netgear WNDR3800 Router
** Motorola SBG6580 Cable Modem
** 2x APC Back-UPS XS 1500 |
05-31-2011
|
#4 | | Windows 7 Ultimate 32-bit & 64-bit both SP1 |
No, that does not mean that MSE will be installed. It's just a suggestion for those using this tool who don't already have an alternative installed. | My System Specs | | System Manufacturer/Model Number Home Built, N/A OS Windows 7 Ultimate 32-bit & 64-bit both SP1 CPU AMD Athlon (tm) 64 X2 Dual Core Processor 7550 @2.5GHz Motherboard Gigabyte GA-MA770-ES3 Memory 2 x 2GB PC2-6400 (DDR2-800), Ganged Mode, (4GB total) Graphics Card Nvidia GeForce GTX 550 Ti 1GB Sound Card Realtek High Definition on board solution (ALC 892) Monitor(s) Displays ViewSonic VA1912w Widescreen (VGA) Screen Resolution 1440x900 Keyboard Microsoft Digital Media Pro Keyboard (USB) Mouse Microsoft Comfort Optical Mouse 3000 (USB) PSU XFX Pro Series 850W Semi-Modular Case Antec NSK 4000B II Cooling 1 x 80mm Front Inlet (with filter) 1 x 120mm Rear Exhaust Hard Drives OCZ Petrol SSD 64GB SATA III
OCZ Petrol SSD 128GB SATA III
Samsung HD501LJ 500GB SATA II x2
Hitachi HDS721010CLA332 1TB SATA II
1 x Iomega 1.5TB Ext USB 2.0 Internet Speed NetGear DG834Gv3 ADSL Modem/Router (Ethernet) ~4.0 Mb/s (O2) Other Info PCI-Express SATA III controller (Marvell 88SE9128 chipset)
Optical Drive: HL-DT-ST BD-RE BH10LS30 SATA Bluray
Lexmark S305 Printer/Scanner/Copier (USB)
CTF-430 Tablet & Pen
WEI Score: |
05-31-2011
|
#5 | | Windows 7 Enterprise x64 SP1 |
Great article Brink!
Another tip regarding update definitions - Update definition on a USB thumb drive
(instructions below are relevant for version 1.0.856.0)
When running the tool again, if the following conditions are met, it will only download definitions (approx. 60MB) and update the USB drive without reformatting it: - A USB thumb drive media is selected.
- The USB drive being has a previously installed Standalone System Sweeper.
- The version that was used to create the bootable media is the same as being used at the second run.
- Files on the USB drive were not damanged or missing (the tool will verify that).
Enjoy!
Guy Arad. | My System Specs | | OS Windows 7 Enterprise x64 SP1 |
05-31-2011
|
#6 | | Windows 7 Ultimate x64 SP1 |
Hello Guy Arad, and welcome to Seven Forums.
Thank you. Added. | My System Specs | | System Manufacturer/Model Number Self built custom OS Windows 7 Ultimate x64 SP1 CPU Intel i7-980X 3.3 Ghz (3.48 Ghz OC'd) Motherboard ASUS P6X58D Premium Memory 12 GB (2GBx6) DDR3 PC3-16000 2000 MHz Kingston HyperX Graphics Card Sapphire HD5870 Eyefinity 6 2GB Sound Card Realtek HD Audio ALC889 Integrated Chip Monitor(s) Displays 3x 27" Asus VE278Q Screen Resolution 1920x1080 Keyboard Logitech Cordless Desktop MX 5500 Revolution Mouse Logitech Cordless Desktop MX 5500 Revolution PSU OCZ Series Gold OCZZ1000M 1000W Case Corsair Obsidian 800D Cooling Thermalright Ultra 120 Extreme Copper CPU heat sink w/120 MM Hard Drives 160GB OCZ RevoDrive X2
** 2 x 1TB Samsung HDD HD154UI SATA Internet Speed 50 Mb/s Download and 2 Mb/s Upload Other Info Microsoft LifeCam Cinema
** Lite-On iHBS212 12x BD Writer
** Samsung CLX-3175FW Printer
** Netgear WNDR3800 Router
** Motorola SBG6580 Cable Modem
** 2x APC Back-UPS XS 1500 |
06-01-2011
|
#7 | | Windows 7 Ult x64 - SP1/ Windows 8 CP x64 |
Great tut, again thanks.
As soon as I saw this, was hoping it was available in an ISO file.
Will add this to my rescue USB tool. | My System Specs | | System Manufacturer/Model Number 76~1.4 OS Windows 7 Ult x64 - SP1/ Windows 8 CP x64 CPU Intel Core i5-750 3.84GHz Motherboard Gigabyte GA-P55A-UD4P, SATA 6Gb/s USB 3, f14 Memory 8GB (2X4GB) DDR3 1600 Corsair Vengeance CL8 1.5v Graphics Card XFX HD 5770 1GB DDR5 Sound Card Realtek HD Audio ALC889 Integrated Chip Monitor(s) Displays 22" LCD Dell Screen Resolution 1680x1050 Keyboard Logitech Wave Mouse CM Sentinel PSU Corsair HX650W Case Cooler Master Storm Scout Cooling Corsair H80 2x12cm Noctua NF P12 , 2x14cm case fans Hard Drives Intel X25 M 120GB SSD,
Seagate Barracuda 500GB SATA2 7200rpm 32MB cache, Seagate Barracuda 1TB SATA2 7200rpm 32MB cache, Internet Speed Dismal Other Info eSATA ports,
External eSATA Seagate 500GB SATA2 7200rpm,
External USB WD 500GB |
06-01-2011
|
#8 | | Windows 7 Enterprise x64 SP1 |

Quote: Originally Posted by Dave76 Great tut, again thanks.
As soon as I saw this, was hoping it was available in an ISO file.
Will add this to my rescue USB tool. I'm glad you are happy with the ISO option. We were hoping it would be of use.
However, if you prepare the ISO now and keep it aside, it will not be up-to-date by the time you are using it (hopefully never  ).
I have two suggestions for you: - Since the tool will reformat your USB, backup your rescue USB drive and create a bootable USB using the tool (you can then copy your data back onto the USB drive), and add the tool binary as well. By the time you have to use, it run the tool again with the same USB drive. The tool will detect the already installed product and will only update the definitions (without reformatting or altering your data).
- The second option is indeed to keep an ISO and when the day comes use Brink's option #1 of manually updating the definitions.
Please keep in mind that the latter option is not currently supported or intended by Microsoft. Use it at your own risk.
Thanks,
Guy. | My System Specs | | OS Windows 7 Enterprise x64 SP1 |
06-01-2011
|
#9 | | Windows 7 Ultimate x64 SP1 |
I found the ISO useful to run at boot on a virtual machine (ex: Windows Virtual PC) to scan it. You can just select the ISO file to act as a "DVD Drive" in the VM's settings to boot from. | My System Specs | | System Manufacturer/Model Number Self built custom OS Windows 7 Ultimate x64 SP1 CPU Intel i7-980X 3.3 Ghz (3.48 Ghz OC'd) Motherboard ASUS P6X58D Premium Memory 12 GB (2GBx6) DDR3 PC3-16000 2000 MHz Kingston HyperX Graphics Card Sapphire HD5870 Eyefinity 6 2GB Sound Card Realtek HD Audio ALC889 Integrated Chip Monitor(s) Displays 3x 27" Asus VE278Q Screen Resolution 1920x1080 Keyboard Logitech Cordless Desktop MX 5500 Revolution Mouse Logitech Cordless Desktop MX 5500 Revolution PSU OCZ Series Gold OCZZ1000M 1000W Case Corsair Obsidian 800D Cooling Thermalright Ultra 120 Extreme Copper CPU heat sink w/120 MM Hard Drives 160GB OCZ RevoDrive X2
** 2 x 1TB Samsung HDD HD154UI SATA Internet Speed 50 Mb/s Download and 2 Mb/s Upload Other Info Microsoft LifeCam Cinema
** Lite-On iHBS212 12x BD Writer
** Samsung CLX-3175FW Printer
** Netgear WNDR3800 Router
** Motorola SBG6580 Cable Modem
** 2x APC Back-UPS XS 1500 Windows Defender Offline problems? All times are GMT -5. The time now is 01:32 AM. |  |