now this is funny too- WD thinks itself is malware

R

robin

In Event View it is telling me there is a change in the registry for WD.
Funny how it says "it might be a result of malware" Windows Defender
doesn't know its own update definition is not malware? <g>

Windows Defender Configuration has changed. If this is an unexpected event
you should review the settings as this may be the result of malware.

Old value: HKLM\SOFTWARE\Microsoft\Windows Defender\Signature
Updates\SignatureLocation = C:\Documents and Settings\All Users\Application
Data\Microsoft\Windows Defender\Definition
Updates\{BAD4329D-A10F-43CD-BCD0-938C2CAF6AC1}

New value: HKLM\SOFTWARE\Microsoft\Windows Defender\Signature
Updates\SignatureLocation = C:\Documents and Settings\All Users\Application
Data\Microsoft\Windows Defender\Definition
Updates\{711C1193-3C40-4045-864B-F45917E08A98}

Robin
 
J

Joe Faulhaber[MSFT]

Hi Robin,

We intentionally did this, actually. The WD registry keys are as well
secured as we could make them, but it's still possible for bad guys to get
to them, so if the config changes, we log events. In this case, I bet it's
expected and perfectly fine, right?

Thanks for trying Windows Defender,
Joe
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top