Microsoft Defender Anti-Malware/Platform Update Kit for Windows 11 (Updated: April 17th, 2025)

Discussion in 'Windows 11' started by steven4554, Jul 3, 2021.

?

Should I drop the arm64 defender cabs for both Windows 10 and 11?

Poll closed Oct 7, 2023.
  1. Yes

    32 vote(s)
    43.8%
  2. No

    12 vote(s)
    16.4%
  3. Maybe/Don't Know

    29 vote(s)
    39.7%
  1. abbodi1406

    abbodi1406 MDL KB0000001

    Feb 19, 2011
    17,438
    92,369
    340
    Is not that a definitions update?

    it's difficult to keep up with Defender / Security updates, it's constant
     
  2. steven4554

    steven4554 MDL Expert

    Jul 12, 2009
    1,546
    2,935
    60
    No that's what I assume is the latest version of the Windows Security Center. But I agree it is constantly updating week by week.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  3. bybeta

    bybeta MDL Novice

    Jun 22, 2015
    6
    2
    0
    The point is that I integrated the latest .cab

    Released: April 17th, 2025
    Next Update: April 25th, 2025
    Defender: 5.4.2504.3
    Engine: 1.1.25030.1
    Platform: 4.18.25030.2
    Version: 1.427.305.0

    And after that, these three updates are showing:


    Windows Malicious Software Removal Tool x64 - v5.132 (KB890830)
    Update for Windows Security platform - KB5007651 (Version 10.0.27777.1008)
    Security Intelligence Update for Microsoft Defender Antivirus - KB2267602 (Version 1.427.312.0) - Current Channel (Broad)
     
  4. boe323

    boe323 MDL Expert

    Jul 19, 2011
    1,824
    562
    60
    Integration doesn't stop regular required updates.
    Intelligence updates are the logic for catching virus's, they are constantly updated with new threats.
    Malicious software removal tool is a scanner that when updated will scan on install, gets updated every few months or so.
     
  5. bybeta

    bybeta MDL Novice

    Jun 22, 2015
    6
    2
    0
    #365 bybeta, Apr 18, 2025 at 17:16
    Last edited: Apr 18, 2025 at 17:24
    Nevermind, just saw that 1.427.312.0 > 1.427.305.0

    My fault, I wasn't reading versions right (lack of sleep maybe). I thought it was just the opposite scenario.

    For the KB5007651 I think the easiest way will be to force update during first boot, as I don't know how to integrate the MUI part of it.
     
  6. TairikuOkami

    TairikuOkami MDL Expert

    Mar 15, 2014
    1,271
    1,188
    60
    Why do you even use MRT, it is pointless.
    Code:
    reg add "HKLM\Software\Policies\Microsoft\MRT" /v "DontOfferThroughWUAU" /t REG_DWORD /d "1" /f
     
  7. bybeta

    bybeta MDL Novice

    Jun 22, 2015
    6
    2
    0
    #367 bybeta, Apr 19, 2025 at 15:05
    Last edited: Apr 19, 2025 at 17:27
    Nah, that policy will be detected by some security tools as tampering; it's easier to run it with a /q from SetupComplete.cmd and call it a day.


    Now I've got the problem with (KB5007651) securityhealthsetup_*.exe, executes and "installs" (or at least, exits without error) but when you open "Windows Security", version is still the old one.
    ...just copies itself to System32\SecurityHealth, with SYSTEM permissions but doesn't get installed.

    Tried both using unattend.xml and SetupComplete.cmd, no luck.
     
  8. steven4554

    steven4554 MDL Expert

    Jul 12, 2009
    1,546
    2,935
    60
    Did you run the executable with admin privileges?
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  9. bybeta

    bybeta MDL Novice

    Jun 22, 2015
    6
    2
    0
    I run them using SYSTEM privileges, via SetupComplete.cmd in first place, on a second run I tried to run it via unattend.xml

    Looks like that installer (securityhealthsetup*) doesn't love OOBE env.

    (However MRT installs without problems that way)