PC Review


Reply
Thread Tools Rate Thread

Comment in event viewer :WinDefend...

 
 
=?Utf-8?B?Q2hhc1g=?=
Guest
Posts: n/a
 
      16th Feb 2006
Each time I start the computer after recently installing"Windows
Defender-Beta 2"
a message is listed in event viewer ,system: Windefend has found malware and
it references ISLNDIS5.sys. I cant find anything wrong, is this significant?
Chas
 
Reply With Quote
 
 
 
 
Bill Sanderson
Guest
Posts: n/a
 
      17th Feb 2006
It is possible that this is a false positive. Googling, I see some
references that seem to associate this with malware, and others that
indicate it is a normal part of networking gear, probably wireless
networking gear.

If you have wireless networking installed, and the location of the
referenced file is consistent with being a part of the drivers for
that--this may be a false positive.

I suspect that this file is being listed as "unknown" rather than known
bad--because you aren't getting an alert from the UI--you can turn that on
in the options settings.

You might write back with the vendor and model of the networking gear and
maybe we can pin this down better.

--

"ChasX" <(E-Mail Removed)> wrote in message
news:C853DB9E-CEC2-4D4F-86D3-(E-Mail Removed)...
> Each time I start the computer after recently installing"Windows
> Defender-Beta 2"
> a message is listed in event viewer ,system: Windefend has found malware
> and
> it references ISLNDIS5.sys. I cant find anything wrong, is this
> significant?
> Chas



 
Reply With Quote
 
=?Utf-8?B?Q2hhc1g=?=
Guest
Posts: n/a
 
      17th Feb 2006
I looked in the history section of WD B2 (I didn't realize there was a
history section)
and the path to the file pointed to the Microsoft broadband networking
utility which was loaded with my Microsoft MS720 wireless card. It must be
safe then to mark it "ignore". The category in history was listed as "not yet
classified". Thanks Bill for your rapid response.
chas

"Bill Sanderson" wrote:

> It is possible that this is a false positive. Googling, I see some
> references that seem to associate this with malware, and others that
> indicate it is a normal part of networking gear, probably wireless
> networking gear.
>
> If you have wireless networking installed, and the location of the
> referenced file is consistent with being a part of the drivers for
> that--this may be a false positive.
>
> I suspect that this file is being listed as "unknown" rather than known
> bad--because you aren't getting an alert from the UI--you can turn that on
> in the options settings.
>
> You might write back with the vendor and model of the networking gear and
> maybe we can pin this down better.
>
> --
>
> "ChasX" <(E-Mail Removed)> wrote in message
> news:C853DB9E-CEC2-4D4F-86D3-(E-Mail Removed)...
> > Each time I start the computer after recently installing"Windows
> > Defender-Beta 2"
> > a message is listed in event viewer ,system: Windefend has found malware
> > and
> > it references ISLNDIS5.sys. I cant find anything wrong, is this
> > significant?
> > Chas

>
>
>

 
Reply With Quote
 
Bill Sanderson
Guest
Posts: n/a
 
      17th Feb 2006
Duh--I have that gear installed some places--I guess I just haven't checked
the event logs on those machines!

Yes--"not yet classified" items are not, by default brought to the users
attention as an alert. This behavior can be changed in Windows Defender,
Tools, General Settings, scroll down to near the end.


--

"ChasX" <(E-Mail Removed)> wrote in message
news:8577BDE0-DF60-46EC-BC06-(E-Mail Removed)...
>I looked in the history section of WD B2 (I didn't realize there was a
> history section)
> and the path to the file pointed to the Microsoft broadband networking
> utility which was loaded with my Microsoft MS720 wireless card. It must
> be
> safe then to mark it "ignore". The category in history was listed as "not
> yet
> classified". Thanks Bill for your rapid response.
> chas
>
> "Bill Sanderson" wrote:
>
>> It is possible that this is a false positive. Googling, I see some
>> references that seem to associate this with malware, and others that
>> indicate it is a normal part of networking gear, probably wireless
>> networking gear.
>>
>> If you have wireless networking installed, and the location of the
>> referenced file is consistent with being a part of the drivers for
>> that--this may be a false positive.
>>
>> I suspect that this file is being listed as "unknown" rather than known
>> bad--because you aren't getting an alert from the UI--you can turn that
>> on
>> in the options settings.
>>
>> You might write back with the vendor and model of the networking gear and
>> maybe we can pin this down better.
>>
>> --
>>
>> "ChasX" <(E-Mail Removed)> wrote in message
>> news:C853DB9E-CEC2-4D4F-86D3-(E-Mail Removed)...
>> > Each time I start the computer after recently installing"Windows
>> > Defender-Beta 2"
>> > a message is listed in event viewer ,system: Windefend has found
>> > malware
>> > and
>> > it references ISLNDIS5.sys. I cant find anything wrong, is this
>> > significant?
>> > Chas

>>
>>
>>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Lots of Event 3004 Windefend error's in the system logfile Skorpio07 Spyware Discussion 2 17th Dec 2007 11:25 PM
Event Viewer cannont connect to remote WinXP SP2 event viewer Russell Windows XP Security 4 3rd Nov 2006 07:22 AM
Warnings Event ID: 3004 from source WinDefend =?Utf-8?B?V2lsbGVt?= Spyware Discussion 0 14th Jul 2006 11:59 AM
WinDefend malware warnings in Event Viewer =?Utf-8?B?T2xkIFJlYmVs?= Spyware Announcements 5 21st Feb 2006 03:35 AM
FAX comment in event viewer shakey Windows XP Help 2 13th Nov 2005 01:15 AM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 12:37 PM.