Event ID 3005 — Real-Time Protection Spyware Removal
Applies To: Windows Server 2008
Windows Defender uses Real-Time Protection to examine auto-start extensibility points (ASEPs). If a change to one of these ASEPs is detected, Windows Defender will alert you. By default, Windows Defender monitors the following ASEPs: applications that are configured to automatically start when the computer starts up, system configuration settings, Internet Explorer Add-ons, Internet Explorer configuration settings, installed services, installed drivers, application registration, and Windows Add-ons.
When Windows Defender raises an alert, it takes the action specified in the definition that detected the spyware or other potentially unwanted software. If Windows Defender incorrectly identified legitimate software, you can allow it to run on the computer. If Windows Defender detected spyware or other potentially unwanted software, you should remove it.
Event Details
Product: | Windows Defender |
ID: | 3005 |
Source: | Microsoft-Windows-Windows Defender |
Version: | 1.1 |
Symbolic Name: | MALWAREPROTECTION_RTP_MALWARE_ACTION_TAKEN |
Message: | %1 Real-Time Protection agent has taken action to protect this machine from spyware or other potentially unwanted software. For more information please see the following: %15 %tScan ID:%b%3 %tUser:%b%8\%9 %tName:%b%11 %tID:%b%12 %tSeverity ID:%b%13 %tCategory ID:%b%14 %tAlert Type:%b%18 %tAction:%b%20 |
Resolve
This is a normal condition. No further action is required.