Very slow cold start due to Defender

Started by esb,

esb

I've noticed very slow cold startup times - the first time after a reboot it can take up to 5-10! seconds for XMPlay to start. All subsequent starts are sub-second fast
After some investigation I've discovered that this is due to Windows Defender, disabling it removes the delay.
And you don't need reboot, a launch from any new location will trigger this behavior (but, unfortunately, any old location will reset after a reboot)

Outside of adding paths as exception in Defender, which I'd like to avoid since it's a portable install in a non-admin location, so any non-admin process can add itself there, can anything be done? Does XMPlay use some "weird" compilation options the Defender is scared of? Executable packing I could revert to make it more Defender-friendly? Anything else?


Windows 10, XMPlay Version 4.1, no themes/plugins (even default DLLs are deleted)

Ian @ un4seen

It isn't taking quite that long here (more like 3 seconds), but it will likely vary with system specs. It will also depend on what files are in XMPlay's folder and subfolders, as XMPlay scans them for plugins/skins and Defender will want to check them too, so you shouldn't have any other (non-plugin/skin/config) files in there to avoid unnecessary delays. Apart from that (and whitelisting the XMPLAY.EXE file), I'm not sure there's anything else you can do about it.

esb

There are no extra files, I've even removed a few included in the archive by default. The thing is that doesn't happen with other players, XMPlay is unfortunately the only one, while I've specifically wanted it due to potential performance of a small player.
I'm also puzzled by why it doesn't persist, thought defender would check on install/first run and that's it...

XMPlay_User

#3
You have you tried add hash MD5 or SHA256 in defender ? I known what also same problem can arise in KIS  , but this not link with XMPlay , simply I known what maybe for some reason antivirus solution doesn't want to work properly with specific program , this not mean what is the program was create bad  , this mean what specific antivirus solution very paranoid and trying see threat in program where this threat absent , such antivirus solutions will every time do running process slower , and in KIS this can solve only if calculate MD5 hash summ and add file , but without specifying the folder
this linked what antivirus solution all more and more trying find digital signature in program , and if this in program absent or digital signature not satisfied antivirus solution , so such prgram every time checking ) even if was add with path , but copy in new folder will checking
I explain what I mean , for exxample.. if prrogram name xmplay.exe and proram in work folder :
c:\programs\program-1\xmplay.exe - so when you add so , for antivirus solution this work as excluded and when you do copy this exe file but path :
c:\programs\program-2\xmplay.exe - then excluded not work even if executable file identicaly , but if you add checksumm MD5 or SHA-256 and leva simply xmplay.exe , then does not mattervalue where you will use this file , does not mattervalue folder name and even letter disk

esb

Quote from: XMPlay_UserYou have you tried add hash MD5 or SHA256 in defender ?

That's only possible in defender enterprise versions, so I can't do that. But I'm surprised Defender doesn't partially do that itself and instead treats a different path as a completely new threat

As a temporary workaround for testing the app I've moved the app to the admin-protected Program Files with an exception

XMPlay_User

Please , do test with hard links , instead of copying file XMPlay.exe from your firstly folder in other folders , you can make NTFS symbolyc links or NTFS hard links , in this cause  Defender will can detect files in diffirent folders no as separate files , but as symbolic link to first folder on PC ) and in theory this can solve your problem )

esb

This doesn't help because I don't move the files, that was just an easy way to demonstrate the issue, which happens on restart even with the files in the same folder

 (not sure whether after some time Defender "forgets" the check and you get another slow start)

XMPlay_User

On logicaly if path add as exclude , defender as any other antivirus solution not must do reset and checking all what available in this folder ) even if add new files and even if in this folder will virus