Microsoft Defender ASR rules remove icons and apps shortcuts from Taskbar
- Reference: 1673616606
- News link: https://www.theregister.co.uk/2023/01/13/happy_friday_13th_microsoft_defender/
- Source link:
The problems were first noted early today, Friday 13th, by multiple IT folk and many seem to be scratching their head as to the cause. Some said they are experiencing it on both Windows 10 and Windows 11.
"I noticed it at around 8.45am (UTC)," one techie at an independent software shop told us. "The ASR rule is removing icons on the taskbar and Start Menu and in some cases uninstalling Microsoft Office as well."
[1]
ASR is designed to make a PC safer by blocking macros etc, but the clean-up is certainly more dramatic than expected. "It just happened, we don't know what caused it.
[2]
[3]
"We suspected it was a KB – a patch from Tuesday – that went wrong but I’ve spoken to plenty of others this morning and we think it is definitely related to the ASR rules."
A [4]thread on Reddit indicates this isn't an isolated incident with other sysadmins jumping in. The person that started the conversation said:
[5]
"We recently onboarded our estate to Defender for Endpoint and we’ve had a number of reports this morning that their program shortcuts (Chrome, Firefox, Outlook have all vanished following a reboot of their machine, which has also occurred for me too. It seems to be blocking from the rule: 'Block Win32 API calls from Office macro'."
Another said they were seeing "exactly the same issue" and had to "push a policy update to set this rule into Audit mode instead of Block – as it's trashing almost all 3rd party apps and even first party ones as you’ve said – Slack, Chrome, Outlook."
"Same. Huge numbers of machines nuked in the past hour. Happy Friday," said another. All Microsoft apps including Excel and Word had also gone AWOL, said yet one more sysadmin.
[6]
Microsoft has so far remained publicly silent on the problem, although it has published MO497128 under the Microsoft 365 Suite category and not the Defender category, warning:
Some users are unable to utilize the Application shortcuts on the Start menu and taskbar ... the shortcut icons may not appear or would not work.
Current status: We're reviewing customer report data to determine our next troubleshooting steps.
Scope of impact: Impact is specific to some users who are served through the affected infrastructure.
One techie has claimed the problem is related to the [7]newest Defender signature (1.381.2140.0). They said it then appears “all shortcuts located ProgramData\Microsoft\Windows\Start Menu\Programs will be deleted instantly.”
Deleting ASR rules worked for one IT pro, and another said it changed the rule to Audit “and it appears to work. The difficulty is that the InTune policy isn’t applying particularly quickly and we also need to repair Office on some machines as the outlook.exe is literally missing (not just the shortcut).”
[8]Windows breaks under upgraded IceXLoader malware
[9]US Supremes deny Pegasus spyware maker's immunity claim
[10]Google warns of commercial Heliconia spyware hitting Chrome, Firefox, Microsoft Defender
[11]Microsoft says it's boosted phishing protection in Windows 11 22H2
In agreement, a poster said: “Set defender ASR rule 92e97fa1-2edf-4476-bdd6-9dd0b4dddc7b to audit only. Confirmed working but will lessen your defences. Big risk if applied org wide, run it by management.”
Frustration then turned to anger. “How in the hell did this update make it past Microsoft testing/QA?? They test before they push updates, right? Guys? Right?”.
And: “Yep Microsoft have fucked it. False Attack Surface alerts for most of Start Menu shortcuts.”
One more added: “Defender really is the Gift that keeps on giving!”
We have asked Microsoft to comment and will update when Redmond makes it to the keyboard. ®
Get our [12]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y8GOMOtm4@qu2G8CFWUjhwAAANg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y8GOMOtm4@qu2G8CFWUjhwAAANg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y8GOMOtm4@qu2G8CFWUjhwAAANg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://www.reddit.com/r/sysadmin/comments/10ar8y3/windows_defender_asrfalsely_blocking_and_removing/
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y8GOMOtm4@qu2G8CFWUjhwAAANg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y8GOMOtm4@qu2G8CFWUjhwAAANg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://www.reddit.com/r/sysadmin/comments/10ar1vb/multiple_users_reporting_microsoft_apps_have/
[8] https://www.theregister.com/2022/11/10/icexloader_malware_microsoft_users/
[9] https://www.theregister.com/2023/01/09/supreme_court_pegasus_spyware/
[10] https://www.theregister.com/2022/12/01/google_heliconia_spyware/
[11] https://www.theregister.com/2022/09/27/microsoft_phishing_password_protect_windows_11/
[12] https://whitepapers.theregister.com/
Have the same issue
How are you pushing the shortcuts back out if you dont mind me asking?
regards
Ranj
Re: Have the same issue
We have grabbed the shortcuts from a reference PC & are pushing them site-wide with SCCM. Some odd ones will need to be manually re-created as people call in.
The only good thing is that ASR works when you access the icon, so if it wasn't clicked, it's still there.
Re: Have the same issue
For anything that's come in via MSIExec, scrape msi install guids and then foreach loop the list through msiexec /fs.
My (extremely quick and dirty) PS code is:
$list = get-wmiobject win32_product | select identifyingnumber
foreach ($thing in $list){
msiexec /fs $thing.identifyingnumber /q
start-sleep 10}
i have a solution
after updating i got the same problem but after googling find out this ASR rule is causing problem "Block Win32 API calls from Office macros"
i have app called defender ui1.10, the much needed ui for defender ..
there i disabled the rule and problem solved.
No real surprise here,.
https://forums.theregister.com/forum/all/2022/11/22/JimmyPage_Anyone_else_have_AppLocker_problems_2_weeks_ago_/
Fucked us up right royally for a day. Nary a peep from anyone.
uninstalling Microsoft Office as well
Finally, an antivirus software is doing its job and people are complaining?
Re: uninstalling Microsoft Office as well
Funny, but not really....
Re: uninstalling Microsoft Office as well
OK, how about: why stop at MS Office? There's also Windows!
Precautions, for your convenience
Of course you must delete icons and shortcuts. These are at the start of most intrusions because people keep clicking on them. When they do, well, shit happens. Better be safe and remove the clickable pictorials and ease of short-pwned-cuts.
Re: Precautions, for your convenience
The best way to reduce attack surface is to "fix" the computer so that it can't even be turned on.
Re: Precautions, for your convenience
Working as designed. It's certainly reducing the attack surface. Think of all the Office macro virus they're safe from!
Job's a good 'un!
My Linux VM
... seems unaffected.
Micro$haft windoze because company policy, but I just start me VM, and beaver away.
Re: My Linux VM
How can you tell if someone's a Linux user?
Don't worry, they'll tell you. Constantly. In discussions where it has zero relevance.
Re: My Linux VM
“Don't worry, they'll tell you”
So you’re saying that vegans use linux ?
See icon.
It is long past time that MS were
sued into oblivion for acts like this.
How is this different from those ransomware infections that stop you from doing business? How many man/woman/person hours has it taken across the globe to remove their F*k ups eh?
rule 1: Add rule to block all MS owned IP addresses to firewall.
Re: It is long past time that MS were
It's different from Ransomware attacks, since most of them offer some hope of a fix if you pony up the readies to them, with MS you just have to wait and see what they'll do next.
Another day wasted - with a price increase of 9% thrown in for good measure.
Thanks, appreciated.
Microsoft Strike again - ASR Rule
Had 2 hours this morning with Microsoft on this informing them they had a problem and they confirmed the problem at 2:40pm. It seems that early this morning, a security policy was updated with additional ability to change the file path for Microsoft products paths for greater security. You can spot this with regression score change in this area. Resulted in the same conditions as previously approx 3 months ago where you can log into web based services, but click to run are not available. I have informed our clients to continue to run web based applications rather than changing any ASR rule to monitor, which may cause more problems than it fixes. Changing the ASR to monitor on a Friday, leaving users and systems open over the weekend where you rely on Microsoft as a single vendor is a bad decision.
Exclusions being added to ASR and then shortcuts being pushed back out... Appears to work in testing on a few PCs