Event ID 1007 — Microsoft Antimalware Engine Spyware Removal

Updated: October 23, 2007

Applies To: Windows Server 2008

green

During a Windows Defender scan, the Microsoft Antimalware Engine quarantines or removes any spyware or potentially unwanted software detected on the computer. When spyware or other potentially unwanted software is quarantined, it is moved to an isolated folder on the computer.

As new definitions are released, items in quarantine can be scanned again to see if the spyware or other potentially unwanted software can be cleaned and released from quarantine. When spyware or other potentially unwanted software is removed, it is deleted from the computer.

Event Details

Product: Windows Defender
ID: 1007
Source: Microsoft-Windows-Windows Defender
Version: 1.1
Symbolic Name: MALWAREPROTECTION_MALWARE_ACTION_TAKEN
Message: %1 has taken action to protect this machine from spyware or other potentially unwanted software.
For more information please see the following:
%15
%tScan ID:%b%3
%tScan Type:%b%5
%tUser:%b%8\%9
%tName:%b%11
%tID:%b%12
%tSeverity ID:%b%13
%tCategory ID:%b%14
%tAction:%b%20

Resolve

This is a normal condition. No further action is required.

Related Management Information

Microsoft Antimalware Engine Spyware Removal

Windows Defender

Community Additions

ADD
Show: