Windows 10: Windows defender, this is something I found in Events viewer after I found the scan logs

Discus and support Windows defender, this is something I found in Events viewer after I found the scan logs in AntiVirus, Firewalls and System Security to solve the problem; Log Name: Microsoft-Windows-Windows Defender/Operational Source: Microsoft-Windows-Windows Defender Date: 9/7/2020 10:43:26 PM... Discussion in 'AntiVirus, Firewalls and System Security' started by chopper5421, Sep 8, 2020.

  1. Windows defender, this is something I found in Events viewer after I found the scan logs


    Log Name: Microsoft-Windows-Windows Defender/Operational
    Source: Microsoft-Windows-Windows Defender
    Date: 9/7/2020 10:43:26 PM
    Event ID: 5007
    Task Category: None
    Level: Information
    Keywords:
    User: SYSTEM
    Computer: DESKTOP-QHAFREC
    Description:
    Windows Defender Antivirus Configuration has changed. If this is an unexpected event you should review the settings as this may be the result of malware.
    Old value: HKLM\SOFTWARE\Microsoft\Windows Defender\Scan\OfflineScanRun = 0x1
    New value: HKLM\SOFTWARE\Microsoft\Windows Defender\Scan\OfflineScanRun = 0x0
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="Microsoft-Windows-Windows Defender" Guid="{11cd958a-c507-4ef3-b3f2-5fd9dfbd2c78}" />
    <EventID>5007</EventID>
    <Version>0</Version>
    <Level>4</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2020-09-08T03:43:26.997168500Z" />
    <EventRecordID>412</EventRecordID>
    <Correlation />
    <Execution ProcessID="2944" ThreadID="5256" />
    <Channel>Microsoft-Windows-Windows Defender/Operational</Channel>
    <Computer>DESKTOP-QHAFREC</Computer>
    <Security UserID="S-1-5-18" />
    </System>
    <EventData>
    <Data Name="Product Name">%%827</Data>
    <Data Name="Product Version">4.18.2008.9</Data>
    <Data Name="Old Value">HKLM\SOFTWARE\Microsoft\Windows Defender\Scan\OfflineScanRun = 0x1</Data>
    <Data Name="New Value">HKLM\SOFTWARE\Microsoft\Windows Defender\Scan\OfflineScanRun = 0x0</Data>
    </EventData>
    </Event>

    Does this look normal????

    :)
     
    chopper5421, Sep 8, 2020
    #1
  2. Tryx3 Win User

    Windows defender ofline scan

    Peter,

    Event viewer maintains a record of the scan starting at

    Application & service logs,

    Microsoft,

    Windows,

    Windows defender,

    Operational,

    Event IDs 2030, 5007

    • WDO failures that Windows knew about would be recorded as EventID 2031
    • but WDO failures while Windows was not running would not be recorded.

    But there is no record of its completion unless it finds malware detections to report in

    Windows defender security centre,

    Virus & threat protection,

    Scan history.

    • The Last scan entry in that dialog refers to Windows defender itself not WDO.

    Denis
     
    Tryx3, Sep 8, 2020
    #2
  3. Location of Windows Defender events saved in Event Viewer

    In this https://docs.microsoft.com/en-us/wi...virus/troubleshoot-windows-defender-antivirus.
    According to the the mentioned link the generated events should be displayed at the following location in the Event Viewer:- Application and Services Logs/Microsoft/Windows/Windows Defender Antivirus/Operational.

    But on performing actions, Events are getting stored at this location in the event viewer:- Application and Services Logs/Microsoft/Windows/Windows Defender/Operational.

    How can I get Microsoft Windows Defender Antivirus folder at this location:- Application and Services Logs/Microsoft/Windows in the event viewer. So that events start getting stored at this location:- Application and Services Logs/Microsoft/Windows/Windows
    Defender Antivirus/Operational.

    ***Original title: Microsoft Defender Antivirus***
     
    Sharoon Austin, Sep 8, 2020
    #3
  4. Windows defender, this is something I found in Events viewer after I found the scan logs

    Windows Defender Scans

    According to the Event Viewer, a Windows Defender Scan is listed it as "Scan Type: Antimalware." Does that include all threats?

    When I do a manual scan, and then go to see the results, the results aren't there and the Scan history usually only lists an automatic scan done at a previous time, and I have to go tot he event viewer to see it. Is there a tool that will allow me to easily view only scans?

    Also, is a quick scan sufficient? What does a scan of the OS drive do that is different that the quick scan?
     
    kitpzyxmsir, Sep 8, 2020
    #4
Thema:

Windows defender, this is something I found in Events viewer after I found the scan logs

Loading...
  1. Windows defender, this is something I found in Events viewer after I found the scan logs - Similar Threads - defender something found

  2. hello, i have a issue with my PC i found this error on event viewer

    in Windows 10 Gaming
    hello, i have a issue with my PC i found this error on event viewer: - <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">- <System> <Provider Name="Microsoft-Windows-Kernel-Power" Guid="{331c3b3a-2005-44c2-ac5e-77220c37d6b4}" /> <EventID>41</EventID> <Version>9</Version> <Level>1</Level> <Task>63</Task>...
  3. hello, i have a issue with my PC i found this error on event viewer

    in Windows 10 Software and Apps
    hello, i have a issue with my PC i found this error on event viewer: - <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">- <System> <Provider Name="Microsoft-Windows-Kernel-Power" Guid="{331c3b3a-2005-44c2-ac5e-77220c37d6b4}" /> <EventID>41</EventID> <Version>9</Version> <Level>1</Level> <Task>63</Task>...
  4. hello, i have a issue with my PC i found this error on event viewer

    in Windows 10 Software and Apps
    hello, i have a issue with my PC i found this error on event viewer: Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">- <System> <Provider Name="Microsoft-Windows-Kernel-Power" Guid="{331c3b3a-2005-44c2-ac5e-77220c37d6b4}" /> <EventID>41</EventID> <Version>9</Version> <Level>1</Level> <Task>63</Task> <Opcode>0</Opcode>...
  5. I am constantly BSODing. This is what I found in the event viewer: "The bugcheck was:...

    in Windows 10 Gaming
    I am constantly BSODing. This is what I found in the event viewer: "The bugcheck was:...: This is the contents of the XML that was returned to me on the Bugcheck.Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">- <System> <Provider Name="Microsoft-Windows-WER-SystemErrorReporting" Guid="{ABCE23E7-DE45-4366-8631-84FA6C525952}"...
  6. I am constantly BSODing. This is what I found in the event viewer: "The bugcheck was:...

    in Windows 10 Software and Apps
    I am constantly BSODing. This is what I found in the event viewer: "The bugcheck was:...: This is the contents of the XML that was returned to me on the Bugcheck.Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">- <System> <Provider Name="Microsoft-Windows-WER-SystemErrorReporting" Guid="{ABCE23E7-DE45-4366-8631-84FA6C525952}"...
  7. I am constantly BSODing. This is what I found in the event viewer: "The bugcheck was:...

    in Windows 10 BSOD Crashes and Debugging
    I am constantly BSODing. This is what I found in the event viewer: "The bugcheck was:...: This is the contents of the XML that was returned to me on the Bugcheck.Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">- <System> <Provider Name="Microsoft-Windows-WER-SystemErrorReporting" Guid="{ABCE23E7-DE45-4366-8631-84FA6C525952}"...
  8. I found something in system 32.

    in Windows 10 Ask Insider
    I found something in system 32.: Type in on the top C:\Windows\System32\SlideToShutDown.exe submitted by /u/Redspeakable [link] [comments] https://www.reddit.com/r/Windows10/comments/q6bed3/i_found_something_in_system_32/
  9. Windows defender Full Scan no threats found but says after that threats are found

    in AntiVirus, Firewalls and System Security
    Windows defender Full Scan no threats found but says after that threats are found: Hi, I recently ran into an issue with windows defender where when I run a full scan the result is: No current threats found and 0 threats found. Then when I restart my computer and look at the message again I get this: [ATTACH] Instead of 0 threats found it says -664...
  10. Windows Defender Antivirus scan history not found

    in AntiVirus, Firewalls and System Security
    Windows Defender Antivirus scan history not found: Hi, When I go to my Windows Security and click on "Protection history" under Scan options as shown in the screenshot below, I can't see any of my scan history although I have done several full and offline scans before, it shows me "No recent actions" and the Windows...