當 Microsoft 支援或工程團隊協助您排除裝置問題時,請使用MpCmdRun.exe以收集 Microsoft Defender 防毒軟體的診斷資料。 將支援套件儲存在受影響的裝置上,或將多個裝置的套件複製到中央位置。
附註
若要改為收集 Defender for Endpoint 的調查套件,請參閱 從裝置收集調查套件。
若遇到 Microsoft Defender 防毒軟體效能問題,請使用 Microsoft Defender 防毒軟體效能分析器。
使用 MpCmdRun 收集診斷資料
在每台受影響的裝置上,請選擇是將診斷套件保留在裝置上,或是將其複製到中央位置:
打開一個升格的命令提示字元(你選擇 以管理員身份執行開啟的命令提示字元視窗),然後使用以下其中一個選項:
將診斷日誌檔案儲存到本地裝置:以下指令會切換到最新的 Microsoft Defender 防毒平台資料夾並建立支援套件:
提示
第一個指令會將目錄變更至 < 中最新版本的 >反惡意程式平台版本
%ProgramData%\Microsoft\Windows Defender\Platform\<antimalware platform version>。 如果該路徑不存在,就會前往%ProgramFiles%\Windows Defender。(set "_done=" & if exist "%ProgramData%\Microsoft\Windows Defender\Platform\" (for /f "delims=" %d in ('dir "%ProgramData%\Microsoft\Windows Defender\Platform" /ad /b /o:-n 2^>nul') do if not defined _done (cd /d "%ProgramData%\Microsoft\Windows Defender\Platform\%d" & set _done=1)) else (cd /d "%ProgramFiles%\Windows Defender")) >nul 2>&1 MpCmdRun.exe -GetFiles依預設,
MpCmdRun.exe會產生、壓縮,並將診斷日誌檔案儲存到C:\ProgramData\Microsoft\Windows Defender\Support\MpSupportFiles.cab。每個裝置的
.cab檔名都一樣。將診斷日誌檔案複製到中央位置:以下語法建立本地支援套件並將其複製到指定的根路徑:
(set "_done=" & if exist "%ProgramData%\Microsoft\Windows Defender\Platform\" (for /f "delims=" %d in ('dir "%ProgramData%\Microsoft\Windows Defender\Platform" /ad /b /o:-n 2^>nul') do if not defined _done (cd /d "%ProgramData%\Microsoft\Windows Defender\Platform\%d" & set _done=1)) else (cd /d "%ProgramFiles%\Windows Defender")) >nul 2>&1 MpCmdRun.exe -GetFiles -SupportLogLocation <RootPath>工具會建立
C:\ProgramData\Microsoft\Windows Defender\Support\MpSupportFiles.cab,然後將.cab檔案以新名稱複製到 的<RootPath>子資料夾(例如,P:\Data或\\Server01\Data)。 複製的檔案使用以下路徑與檔名語法:<RootPath>\<MMDD>\MpSupport-<Hostname>-<HHMM>.cab。-
<RootPath>是你指定給的-SupportLogLocation值。 -
<MMDD>是你執行 MpCmdRun 命令當天的月份和日期(例如,0318 代表 3 月 18 日)。 -
<Hostname>是你執行 MpCmdRun 指令的裝置名稱,例如 (LAPTOP01) 。 -
<HHMM>是你執行 MpCmdRun 指令時的整點和分(例如2221,22:21)。
-
附註
如果工具無法將
.cab檔案複製到指定位置,請檢查位於C:\ProgramData\Microsoft\Windows Defender\Support\MpSupportFiles.cab的預設本機位置。以下範例於3月18日22:21複製了名為LAPTOP01的裝置的支援套件:
(set "_done=" & if exist "%ProgramData%\Microsoft\Windows Defender\Platform\" (for /f "delims=" %d in ('dir "%ProgramData%\Microsoft\Windows Defender\Platform" /ad /b /o:-n 2^>nul') do if not defined _done (cd /d "%ProgramData%\Microsoft\Windows Defender\Platform\%d" & set _done=1)) else (cd /d "%ProgramFiles%\Windows Defender")) >nul 2>&1 MpCmdRun.exe -GetFiles -SupportLogLocation "\\SERVER01\Data"所得
.cab檔案可於\\SERVER01\Data\0318\MpSupport-LAPTOP01-2221.cab。 檔案名稱中的主機名稱與時間區分來自不同裝置的檔案。等待幾分鐘,讓
MpCmdRun.exe產生並壓縮診斷記錄檔。 最終檔案.cab包含:- 任何來自 Microsoft Antimalware Service 的追蹤檔案。
- Windows Update 歷史紀錄。
- 系統事件日誌中所有 Microsoft Antimalware Service 事件。
- 所有相關的 Microsoft Antimalware Service 登錄位置。
- MpCmdRun 的日誌檔。
- 簽名更新輔助工具的日誌檔。
將檔案複製
.cab到Microsoft支援能存取的安全位置,例如有密碼保護的OneDrive資料夾。
請使用群組原則設定診斷檔案複製位置
設定 定義用來複製支援記錄檔的目錄路徑 政策,以便在 MpCmdRun.exe 於每部裝置上建立診斷套件後,將其複製到中央位置。 當你設定這個政策時,不需要使用 -SupportLogLocation 帶有 MpCmdRun.exe -GetFiles的選項。
請使用「使用群組政策配置 Microsoft Defender 防毒軟體」中的程序,開啟並編輯適用於目標裝置的群組政策物件(GPO)。 對於基於網域的群組政策,你可以在 群組政策中央儲存庫中管理範本。
要設定診斷檔案複製位置:
在群組原則管理編輯器中,請前往電腦設定>管理範本>Windows 組件>Microsoft Defender 防毒軟體。
開啟 定義目錄路徑以複製支援日誌檔案。
選取 已啟用。 在 選項中,輸入你希望工具複製支援套件的目錄路徑。
請選擇 [確定]。
此原則會設定 HKLM\Software\Policies\Microsoft\Windows Defender 下的 SupportLogLocation 值。