I believe Defender does scan newly downloaded files as a matter of course and doesn't wait for a scheduled scan. That could account for why you can't see a scan happening yet the task is active.
I wonder if doing the update in Safe mode would prevent Defender working, and allow the upgrade through more quickly? Of course you'd have needed to have downloaded the update before rebooting into Safe as you wouldn't really want to be online without Defender.
I think these Microsoft links will get you the package you are sticking on
64 bit download.windowsupdate.com/d/msdownload/update/software/updt/2018/07/windows10.0-kb4345421-x64_c5a035dc1ec030a5be0626c8b019b9c4f6e8a1a6.msu
32 bit
download.windowsupdate.com/c/msdownload/update/software/updt/2018/07/windows10.0-kb4345421-x86_74331e092aa326fc34f320ecc46e56d88017887b.msu
The 64 bit package is nearly 700mb so really would genuinely take some time to scan... and require a useful lump of spare disk space!! Especially as Windows tries to save the old version before upgrading to the new one.
(You can clear old versions of Windows through File Manager - right click on your disk, go to properties, general, disk cleanup, click Clean Up System Files and select which ones to clear - you'll see that sometimes there is a huge amount of data taken up by them!!)
You may even find that just downloading and then running these files would not go through the same process as the automated update and may work OK.
Till the next time :-)
|