Bill,
Thanks for your response. Below are the 3 sys events relevent to the
situation. I believe AntiVir was shut down (entry 3)because of the error
caused by Defender (entry 2) which caused Explorer to restart.
I have reinstalled Defender to keep WOC happy, and it immediately popped up
a window different from the notifications received yesterday and today,
(where all I could do was click Ignore), that requested "Always Allow" which
I promptly clicked! I will see if the situation has been remedied thusly,
but I sure am aggravated that Defender ignored ME when I told IT to ignore
TClock!
Another quick question.....does Defender live happily with Vista? We are
getting event ID 3004 and 3005 warnings on our Vista test machine
consistently. Software name is "unknown" so we can't track the exact
problem.
Thanks muchly.
ENTRY 1
Event Type: Warning
Event Source: WinDefend
Event Category: None
Event ID: 1006
Date: 6/15/2006
Time: 12:54:37 PM
User: N/A
Computer: N1
Description:
Windows Defender scan has detected spyware or other potentially unwanted
software.
For more information please see the following:
http://www.microsoft.com
Scan ID: {7A955E4D-86AE-4527-90DC-08FC49764996}
Scan Type: AntiSpyware
Scan Parameters: Full Scan
User: NT AUTHORITY\NETWORK SERVICE
Name: Tclock
ID: 17380
Severity ID: 1
Category ID: 27
Path Found:
process

id:1856;file

:\Downloads\tclocklight-040702-3.zip->tcdll.tclock;file

:\Documents
and Settings\Nan\Desktop\tclocklight-040702-3[1]\TCDLL.TCLOCK;file:C:\System
Volume
Information\_restore{E552D819-11E2-4279-993E-3729DEACB3B7}\RP463\A0036683.lnk
Detection Type: Signatures
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
ENTRY 2
Event Type: Error
Event Source: WinDefend
Event Category: None
Event ID: 1008
Date: 6/15/2006
Time: 12:55:12 PM
User: N/A
Computer: N1
Description:
Windows Defender has encountered an error when taking action on spyware or
other potentially unwanted software.
For more information please see the following:
http://www.microsoft.com
Scan ID: {7A955E4D-86AE-4527-90DC-08FC49764996}
Scan Type: AntiMalware
User: NT AUTHORITY\NETWORK SERVICE
Name: Tclock
ID: 17380
Severity ID: 1
Category ID: 27
Path:
Action: Quarantine
Error Code: 0x80508022
Error description:
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
ENTRY 3
Event Type: Information
Event Source: Winlogon
Event Category: None
Event ID: 1002
Date: 6/15/2006
Time: 12:55:13 PM
User: N/A
Computer: N1
Description:
The shell stopped unexpectedly and Explorer.exe was restarted.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.