Thanks--If I find such messages in log files on my servers, I'll reply to
this thread. I haven't seen any notifications from the UI.
--
"Joe Faulhaber [MSFT]" <(E-Mail Removed)> wrote in
message news:6CA5E452-B202-4451-9A0E-(E-Mail Removed)...
> Actually, this is mostly by design, though that event should communicate
> more
> clearly. It's very interesting that you didn't see the UI tell you about
> this - the event means that the UI got notified of the change. Hmmm.
> It's
> possible it came through when shutting down, can you tell from the log?
>
> But this isn't really a false positive - this driver is unknown to us, and
> the UI submitted it to spynet for analysis.
>
> Thanks for trying Windows Defender,
> Joe
>
>
>
>
>
> "Bill Sanderson" wrote:
>
>> I think I have that on some machines--I'll check the event logs--good
>> catch.
>>
>> If you get the chance--could you post this in the .signatures, group,
>> too?
>>
>> Thats where false positive reports should go--and this is of that ilk.
>> --
>>
>> "balem" <(E-Mail Removed)> wrote in message
>> news:A914610C-F693-41A7-B8A7-(E-Mail Removed)...
>> >I have User Profiles Hive Cleanup version 1.6.30 installed.
>> >
>> > Event Viewer showing warning log but no notification or warning from
>> > Window
>> > Defender at all even When Changing Notification option. I see this log
>> > shows
>> > up when restarting, log-off computer. I'm Wondering What's going on?
>> >
>> > Type: Warning Event:3004 Source: WinDefend
>> > Windows Defender Real-Time Protection agent has detected potential
>> > malware.
>> >
>> > Threat Name: Unknown
>> > Threat Id:
>> > Threat Severity:
>> > Threat Category:
>> > Path Found: driver: uphcleanhlp
>> > Threat Classification: Unknown
>> > Detection Type:
>>
>>
>>
|