Sysprep Executor Detecting Defender
I am currently preparing an image that I upgraded to 1903 and I have not had an issue with this image before upgrading to 1903. When I run the Sysprep Executor (v220.127.116.11) it says Windows Defender is still running. Under defender settings, real-time protection is switched off (and shows off by administrator).
Here are the things I have tried:
- Disabled via group policy "Computer Configuration\Administrative Templates\Windows Components\Windows Defender Antivirus\Turn off Windows Defender Antivirus"
- Disabled "Windows Security notification icon" from startup via Task Manager.
- Set registry key
When Sysprep Executor runs, it says "disabling real-time protection" as it starts, but checklist screen, it says "*Antivirus Detected".
Community Chosen Answer
If you put your cursor of the Antivirus detected message you should see a tool tip indicating what AV is detected. It uses a WMI call to get this information.