False positive for the last 10 days

P

Pierre Szwarc

TClock Lite (http://homepage1.nifty.com/kazubon/tclocklight/index.html), a
highly customizable notification area clock, has been detected as a low risk
and repeatedly flagged in each scan, in spite of my marking it as "ignored"
each time.

Environment: Windows XP Pro French version, fully up-to-date with automatic
updates.

These are the relevant events from the system log:

----------------------------------------
Windows Defender scan has started.
Scan ID: {A1722A52-E2A0-493D-AF08-2D25AB6B7C73}
Scan Type: AntiSpyware
Scan Parameters: Quick Scan
User: AUTORITE NT\SERVICE RÉSEAU


Pour plus d'informations, consultez le centre Aide et support à l'adresse
http://go.microsoft.com/fwlink/events.asp.
----------------------------------------

Windows Defender scan has detected spyware or other potentially unwanted
software.
For more information please see the following:
http://www.microsoft.com
Scan ID: {A1722A52-E2A0-493D-AF08-2D25AB6B7C73}
Scan Type: AntiSpyware
Scan Parameters: Quick Scan
User: AUTORITE NT\SERVICE RÉSEAU
Name: Tclock
ID: 17380
Severity ID: 1
Category ID: 27
Path Found: process:pid:2720;file:C:\Program
Files\Accessoires\TClock\TCDLL.TCLOCK
Detection Type: Signatures


Pour plus d'informations, consultez le centre Aide et support à l'adresse
http://go.microsoft.com/fwlink/events.asp.
----------------------------------------

Windows Defender scan has finished.
Scan ID: {A1722A52-E2A0-493D-AF08-2D25AB6B7C73}
Scan Type: AntiSpyware
Scan Parameters: Quick Scan
User: AUTORITE NT\SERVICE RÉSEAU
Scan Time: 0:01:59


Pour plus d'informations, consultez le centre Aide et support à l'adresse
http://go.microsoft.com/fwlink/events.asp.
----------------------------------------

Windows Defender has taken action to protect this machine from spyware or
other potentially unwanted software.
For more information please see the following:
http://www.microsoft.com
Scan ID: {A1722A52-E2A0-493D-AF08-2D25AB6B7C73}
Scan Type: AntiMalware
User: SZWARC-VAIO\Pierre
Name: Tclock
ID: 17380
Severity ID: 1
Category ID: 27
Action: Ignore


Pour plus d'informations, consultez le centre Aide et support à l'adresse
http://go.microsoft.com/fwlink/events.asp.
 
J

Joe Faulhaber[MSFT]

Hi Pierre,

Thanks for including the detection details...
Please select "Ignore alwyas" for TClock next time it's detected, and it
will be put on the "Allowed items" list. Then you won't get nagged about it
any longer.

Thanks for trying Windows Defender,
Joe
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top