Eicar.com test - 185 Registry Keys removed????

  • 6 December 2013
  • 1 reply
  • 31 views

Userlevel 4
Badge +16
Hello.  I have the latest version (4.0.4.42) running on my system and just wanted to see what happens with the cleaning, so I downloaded eicar.com file from the Eicar web site.  I'm not questioning the web filtering but along with removing the downloaded file (and the quarantined file from Windows Defender removing the file {the threat log shows BOTH files being removed}) WSA also removed 185 registry entries and placed them in quarantine.  These are all Internet Zone Domains keys.
 
Has anyone else seen anything similar?  Why do the Treats Removed on the main GUI not include the 185 objects in quarantine that WSA placed there?  Would a working web shield block the download so that only WSA reacts to the file and then you don't have WSA AND Windows Defender handling the same file at the same time?
 
I'd post a screen shot but I seem to not have the ability to add images anywhere on this forum.  Plesse don't misunderstand me; I LIKE WSA very much (just bought a 1yr/5device license and talked my wife into using it also).  So much has changed from the first beta of WSA until now that I'm just trying to wrap my head around what it does, what it doesn't and what it should.
 
Thanks.

1 reply

Userlevel 7
Badge +56
I would suggest to Submit a Support Ticket and they can look into it futher and they would be able to give you better anwsers.
 
Daniel 😉

Reply