Windows Defender found something

  • Thread starter Thread starter Guest
  • Start date Start date
G

Guest

Hi
I was looking through the Event Log/Viewer in the Systems messages section.
I got these two messages:

Scan ID: {F470D05A-4DE0-4EB9-BA15-2C76A4B57516}
User: <my machine>\<my account>
Name: Unknown
ID:
Severity ID:
Category ID:
Path Found: driver:IPSEC
Alert Type: Unclassified software
Detection Type:

Scan ID: {C9DA80B0-9538-46F1-BA23-76171572D6FE}
User: <my machine>\<my account>
Name: Unknown
ID:
Severity ID:
Category ID:
Path Found: service:IPSEC
Alert Type: Unclassified software
Detection Type:

Should I be concerned? It didnt provide a path to the executable so I dont
know where those files are.
I am running Vista Business edition.
Windows Defender / Tools/ Software Explorer doesnt show them.
Windows Defender Quarrentine doesnt show them either ?

Defender should recognize Vista's own files right?

I did try to install Cisco VPN but that was uninstalled a few days ago.
 
IPSEC is a system Service so you shouldn't expect to see anything under
software explorer, allowed items, quarantine, etc.... Also, there will be no
file path associated with IPSEC. I tend to agree with you that Windows
Defender should know about Microsoft stuff. Under Tools->Options->Real time
protection options->Choose if Windows Defender should notify you about, maybe
you have the box "Changes made to your computer by software that is permitted
to run" checked? It is possible that this is a Vista issue - not sure.
However, I would not be alarmed by the entry.
 
Back
Top