收集 Microsoft Defender 防毒軟體診斷資料

當 Microsoft 支援或工程團隊協助您排除裝置問題時,請使用MpCmdRun.exe以收集 Microsoft Defender 防毒軟體的診斷資料。 將支援套件儲存在受影響的裝置上,或將多個裝置的套件複製到中央位置。

附註

若要改為收集 Defender for Endpoint 的調查套件,請參閱 從裝置收集調查套件。

若遇到 Microsoft Defender 防毒軟體效能問題,請使用 Microsoft Defender 防毒軟體效能分析器。

使用 MpCmdRun 收集診斷資料

在每台受影響的裝置上,請選擇是將診斷套件保留在裝置上,或是將其複製到中央位置:

  1. 打開一個升格的命令提示字元(你選擇 以管理員身份執行開啟的命令提示字元視窗),然後使用以下其中一個選項:

    • 將診斷日誌檔案儲存到本地裝置:以下指令會切換到最新的 Microsoft Defender 防毒平台資料夾並建立支援套件:

      提示

      第一個指令會將目錄變更至 < 中最新版本的 >反惡意程式平台版本%ProgramData%\Microsoft\Windows Defender\Platform\<antimalware platform version>。 如果該路徑不存在,就會前往 %ProgramFiles%\Windows Defender。

      (set "_done=" & if exist "%ProgramData%\Microsoft\Windows Defender\Platform\" (for /f "delims=" %d in ('dir "%ProgramData%\Microsoft\Windows Defender\Platform" /ad /b /o:-n 2^>nul') do if not defined _done (cd /d "%ProgramData%\Microsoft\Windows Defender\Platform\%d" & set _done=1)) else (cd /d "%ProgramFiles%\Windows Defender")) >nul 2>&1
      
      MpCmdRun.exe -GetFiles
      

      依預設,MpCmdRun.exe 會產生、壓縮,並將診斷日誌檔案儲存到 C:\ProgramData\Microsoft\Windows Defender\Support\MpSupportFiles.cab。

      每個裝置的 .cab 檔名都一樣。

    • 將診斷日誌檔案複製到中央位置:以下語法建立本地支援套件並將其複製到指定的根路徑:

      (set "_done=" & if exist "%ProgramData%\Microsoft\Windows Defender\Platform\" (for /f "delims=" %d in ('dir "%ProgramData%\Microsoft\Windows Defender\Platform" /ad /b /o:-n 2^>nul') do if not defined _done (cd /d "%ProgramData%\Microsoft\Windows Defender\Platform\%d" & set _done=1)) else (cd /d "%ProgramFiles%\Windows Defender")) >nul 2>&1
      
      MpCmdRun.exe -GetFiles -SupportLogLocation <RootPath>
      

      工具會建立 C:\ProgramData\Microsoft\Windows Defender\Support\MpSupportFiles.cab,然後將 .cab 檔案以新名稱複製到 的 <RootPath> 子資料夾(例如, P:\Data 或 \\Server01\Data)。 複製的檔案使用以下路徑與檔名語法: <RootPath>\<MMDD>\MpSupport-<Hostname>-<HHMM>.cab。

      • <RootPath> 是你指定給的 -SupportLogLocation值。
      • <MMDD> 是你執行 MpCmdRun 命令當天的月份和日期(例如,0318 代表 3 月 18 日)。
      • <Hostname> 是你執行 MpCmdRun 指令的裝置名稱,例如 (LAPTOP01) 。
      • <HHMM> 是你執行 MpCmdRun 指令時的整點和分(例如 2221 ,22:21)。

    附註

    如果工具無法將 .cab 檔案複製到指定位置,請檢查位於 C:\ProgramData\Microsoft\Windows Defender\Support\MpSupportFiles.cab 的預設本機位置。

    以下範例於3月18日22:21複製了名為LAPTOP01的裝置的支援套件:

    (set "_done=" & if exist "%ProgramData%\Microsoft\Windows Defender\Platform\" (for /f "delims=" %d in ('dir "%ProgramData%\Microsoft\Windows Defender\Platform" /ad /b /o:-n 2^>nul') do if not defined _done (cd /d "%ProgramData%\Microsoft\Windows Defender\Platform\%d" & set _done=1)) else (cd /d "%ProgramFiles%\Windows Defender")) >nul 2>&1
    
    MpCmdRun.exe -GetFiles -SupportLogLocation "\\SERVER01\Data"
    

    所得 .cab 檔案可於 \\SERVER01\Data\0318\MpSupport-LAPTOP01-2221.cab。 檔案名稱中的主機名稱與時間區分來自不同裝置的檔案。

  2. 等待幾分鐘,讓 MpCmdRun.exe 產生並壓縮診斷記錄檔。 最終檔案 .cab 包含:

    • 任何來自 Microsoft Antimalware Service 的追蹤檔案。
    • Windows Update 歷史紀錄。
    • 系統事件日誌中所有 Microsoft Antimalware Service 事件。
    • 所有相關的 Microsoft Antimalware Service 登錄位置。
    • MpCmdRun 的日誌檔。
    • 簽名更新輔助工具的日誌檔。

    將檔案複製.cab到Microsoft支援能存取的安全位置,例如有密碼保護的OneDrive資料夾。

請使用群組原則設定診斷檔案複製位置

設定 定義用來複製支援記錄檔的目錄路徑 政策,以便在 MpCmdRun.exe 於每部裝置上建立診斷套件後,將其複製到中央位置。 當你設定這個政策時,不需要使用 -SupportLogLocation 帶有 MpCmdRun.exe -GetFiles的選項。

請使用「使用群組政策配置 Microsoft Defender 防毒軟體」中的程序,開啟並編輯適用於目標裝置的群組政策物件(GPO)。 對於基於網域的群組政策,你可以在 群組政策中央儲存庫中管理範本。

要設定診斷檔案複製位置:

  1. 在群組原則管理編輯器中,請前往電腦設定>管理範本>Windows 組件>Microsoft Defender 防毒軟體。

    在主控台樹中選擇 Microsoft Defender 防毒軟體時,本地群組原則編輯器的截圖。

  2. 開啟 定義目錄路徑以複製支援日誌檔案。

  3. 選取 已啟用。 在 選項中,輸入你希望工具複製支援套件的目錄路徑。

    本地群組原則編輯器截圖,選項區段已選為啟用,並輸入路徑值。

  4. 請選擇 [確定]。

此原則會設定 HKLM\Software\Policies\Microsoft\Windows Defender 下的 SupportLogLocation 值。