Symptoms:
- The SolarWinds web console returns
Server Error in '/' Application or does not load. - SolarWinds services fail to start or repeatedly stop.
- SAM jobs, orchestration, job scheduling, SWIS communication, or polling are impaired.
- Defender history shows multiple SolarWinds files quarantined or remediated
Cause:
So far, confirmed defender versions are:
- 1.457.394.0
- 1.457.399.0
- 1.457.401.0
- 1.457.407.0
Currently confirmed files affected:
- \solarwinds\orion\seum\player\solarwinds.seum.agentdomainconfigurationtool.exe
- \solarwinds\orion\solarwinds.ncm.strings.dll
- \solarwinds\orion\web\apps\bin
ats.client.hosting.dll - \solarwinds\orion\solarwinds.diagnostics.contract.dll
- \solarwinds\orion\solarwinds.credentials.oauth2.dll
- \solarwinds\orion\web\api2\bin\solarwinds.orion.identity.models.dll
- \solarwinds\orion\web\bin\solarwinds.orion.eoc.models.dll
- \solarwinds\orion\solarwinds.orion.activediagnostics.contract.dll
internalbehavior: B254ED5DA269F3C6DC763DD6E50BDFC2
Resolution:
Steps to validate the defender version:
- Open powershell
- Run the command
Get-MpComputerStatus |Select AMProductVersion, AMEngineVersion, AntivirusSignatureVersion
The version release date can be validated from:
https://www.microsoft.com/en-us/wdsi/definitions/antimalware-definition-release-notes
?
Workaround 1:
- Add the SolarWinds folder to the Defender exclusion list.**
- Restore any SolarWinds files quarantined by Microsoft Defender.
- Run the SolarWinds Configuration Wizard
- Verify that they start successfully.
Workaround 2. (If Dependecy is missing - RMQ, SWA and .Net Shared Network)
- Add the SolarWinds folder to the Defender exclusion list.**
- Restore any SolarWinds files quarantined by Microsoft Defender.
- Do a repair in the control panel > Solarwinds
- Run the Configuration Wizard after
**Steps to Add a Folder Exclusion
- Click the Start menu or taskbar search box and type Windows Security.
- Open the Windows Security app from the search results.
- Select Virus & threat protection from the side menu or main dashboard.
- Under Virus & threat protection settings, click Manage settings.
- Scroll down to the Exclusions section and click Add or remove exclusions.
- Click the + Add an exclusion button and select Folder from the drop-down menu.
- Browse your computer, select the folder you want to ignore, and click Select Folder.
In some cases, disabling Windows Defender might not work.
If that's the case, please have it checked with the customer security team.
Some possible reasons:
- A managed policy is overriding the local setting.
- The detection is from another Defender capability.
- The file was already quarantined or removed.
- Another security product is still active.