Solved Windows Security Scan - unknown threat detected


mrmatt

Member
Local time
6:34 PM
Posts
104
Location
UK
OS
Windows 11 Home 25H2 26200.9457
Just ran a full scan with Windows Security. It reported one threat found.

However, I've tried looking in Protection History. I've no idea what it thought it found, there's nothing showing.

Any ideas please ?
 

My Computer My Computer

At a glance

Windows 11 Home 25H2 26200.9457
OS
Windows 11 Home 25H2 26200.9457
Computer type
PC/Desktop
Manufacturer/Model
HP
Restart and see if it appears in protection history.
Check event viewer- Applications and Services Logs >Microsoft > Windows > Windows Defender>→ Operational
Run another manual scan.

It may well have benn nothing of note.It could have been a harmless transient detection, false positive, or an auto-remediated item that never made it into Protection History
 

My Computers My Computers

  • At a glance

    Windows 11 Pro 25H2 26200.9457i9-10900 10 core 20 threads32 gbnone-Intel UHD Graphics 630
    OS
    Windows 11 Pro 25H2 26200.9457
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Optiplex 7080
    CPU
    i9-10900 10 core 20 threads
    Motherboard
    DELL 0J37VM
    Memory
    32 gb
    Graphics Card(s)
    none-Intel UHD Graphics 630
    Sound Card
    Integrated Realtek
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    2x1tb Solidigm m.2 nvme /External drives 512gb Samsung m.2 sata+2tb Kingston m2.nvme
    PSU
    500w
    Case
    MT
    Cooling
    Dell Premium
    Keyboard
    Logitech wired
    Mouse
    Logitech wireless
    Internet Speed
    so slow I'm too embarrassed to tell
    Browser
    #1 Edge #2 Firefox
    Antivirus
    Defender+MWB Premium
  • At a glance

    Windows 11 Pro 24H2 26200.9457AMD Ryzen 7 6800U32 gbintegrated
    Operating System
    Windows 11 Pro 24H2 26200.9457
    Computer type
    PC/Desktop
    Manufacturer/Model
    Beelink Mini PC SER5
    CPU
    AMD Ryzen 7 6800U
    Memory
    32 gb
    Graphics card(s)
    integrated
    Sound Card
    integrated
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    1TB Crucial nvme
    Keyboard
    Logitech wired
    Mouse
    Logitech wireless
    Internet Speed
    still too embarrassed to tell
    Browser
    Firefox
    Antivirus
    Defender
  • System 3 is non compliant Dell 9020 i7-4770/24gb ram Win11 PRO 26200.9457
I wasn't even given any options as to what to do with it.
 

My Computer My Computer

At a glance

Windows 11 Home 25H2 26200.9457
OS
Windows 11 Home 25H2 26200.9457
Computer type
PC/Desktop
Manufacturer/Model
HP
So..........

I've just restarted the PC, did another Full Scan.


Windows Defender reported that it 'took action against a threat'. But again no info. Why not ? I couldn't even see anything listed in Protection History again. So I followed your instructions.


Here is the log:

Code:
Log Name:      Microsoft-Windows-Windows Defender/Operational
Source:        Microsoft-Windows-Windows Defender
Date:          10/08/2026 17:14:38
Event ID:      1160
Task Category: None
Level:         Warning
Keywords:    
User:          SYSTEM
Computer:      DESKTOP-1BCOBNU
Description:
Microsoft Defender Antivirus has detected potentially unwanted application(PUA).
 For more information please see the following:
[URL unfurl="true"]https://go.microsoft.com/fwlink/?linkid=37020&name=PUABundler:Win32/Rostpay&threatid=311954&enterprise=0[/URL]
     Name: PUABundler:Win32/Rostpay
     ID: 311954
     Severity: Low
     Category: Potentially Unwanted Software
     Path: file:_C:\Users\Wendy\Documents\Matt's Docs\driver-hub-install__28.exe
     Detection Origin: Local machine
     Detection Type: Concrete
     Detection Source: User
     User: DESKTOP-1BCOBNU\Wendy
     Process Name: Unknown
     Security intelligence Version: AV: 1.457.96.0, AS: 1.457.96.0, NIS: 1.457.96.0
     Engine Version: AM: 1.1.26070.7, NIS: 1.1.26070.7
Event Xml:
<Event xmlns="[URL]http://schemas.microsoft.com/win/2004/08/events/event[/URL]">
  <System>
    <Provider Name="Microsoft-Windows-Windows Defender" Guid="{11cd958a-c507-4ef3-b3f2-5fd9dfbd2c78}" />
    <EventID>1160</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2026-08-10T16:14:38.7938419Z" />
    <EventRecordID>14323</EventRecordID>
    <Correlation ActivityID="{c4d6cfc3-5c7e-4e6b-b03e-3d5ff1428b8b}" />
    <Execution ProcessID="5348" ThreadID="15516" />
    <Channel>Microsoft-Windows-Windows Defender/Operational</Channel>
    <Computer>DESKTOP-1BCOBNU</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="Product Name">Microsoft Defender Antivirus</Data>
    <Data Name="Product Version">4.18.26070.9</Data>
    <Data Name="Detection ID">{69219CEF-182B-48CE-9F6C-040827FEAB8A}</Data>
    <Data Name="Detection Time">2026-08-10T16:14:38.739Z</Data>
    <Data Name="Unused">
    </Data>
    <Data Name="Unused2">
    </Data>
    <Data Name="Threat ID">311954</Data>
    <Data Name="Threat Name">PUABundler:Win32/Rostpay</Data>
    <Data Name="Severity ID">1</Data>
    <Data Name="Severity Name">Low</Data>
    <Data Name="Category ID">27</Data>
    <Data Name="Category Name">Potentially Unwanted Software</Data>
    <Data Name="FWLink">[URL='https://go.microsoft.com/fwlink/?linkid=37020&name=PUABundler:Win32/Rostpay&threatid=311954&enterprise=0']Cyberthreats, viruses, and malware - Microsoft Security Intelligence[/URL]</Data>
    <Data Name="Status Code">1</Data>
    <Data Name="Status Description">
    </Data>
    <Data Name="State">1</Data>
    <Data Name="Source ID">1</Data>
    <Data Name="Source Name">User</Data>
    <Data Name="Process Name">Unknown</Data>
    <Data Name="Detection User">DESKTOP-1BCOBNU\Wendy</Data>
    <Data Name="Unused3">
    </Data>
    <Data Name="Path">file:_C:\Users\Wendy\Documents\Matt's Docs\driver-hub-install__28.exe</Data>
    <Data Name="Origin ID">1</Data>
    <Data Name="Origin Name">Local machine</Data>
    <Data Name="Execution ID">0</Data>
    <Data Name="Execution Name">Unknown</Data>
    <Data Name="Type ID">0</Data>
    <Data Name="Type Name">Concrete</Data>
    <Data Name="Pre Execution Status">0</Data>
    <Data Name="Action ID">9</Data>
    <Data Name="Action Name">Not Applicable</Data>
    <Data Name="Unused4">
    </Data>
    <Data Name="Error Code">0x00000000</Data>
    <Data Name="Error Description">The operation completed successfully. </Data>
    <Data Name="Unused5">
    </Data>
    <Data Name="Post Clean Status">0</Data>
    <Data Name="Additional Actions ID">0</Data>
    <Data Name="Additional Actions String">No additional actions required</Data>
    <Data Name="Remediation User">
    </Data>
    <Data Name="Unused6">
    </Data>
    <Data Name="Security intelligence Version">AV: 1.457.96.0, AS: 1.457.96.0, NIS: 1.457.96.0</Data>
    <Data Name="Engine Version">AM: 1.1.26070.7, NIS: 1.1.26070.7</Data>
  </EventData>
</Event>

I've there decided against using it, and deleted it. It's not really a virus, but Windows Security doesn't trust it.


Thank you very much for your reply. Very informative, very helpful. I didn't know that. At least hopefully I'll remember for in the future. I don't know why MS makes that info difficult to find though.
 
Last edited by a moderator:

My Computer My Computer

At a glance

Windows 11 Home 25H2 26200.9457
OS
Windows 11 Home 25H2 26200.9457
Computer type
PC/Desktop
Manufacturer/Model
HP
@Bree,

I have never heard of an EventID 1160 as posted above. Have you?

I thought PUAs would be recorded as EventID 1117.
Defender EventIDs - MSLearn does not list 1160 but it clearly does exist.
There's nothing in the discussion at Block PUAs - MSLearn either.
[My event logs do not contain any 1160s.]

Any thoughts? Possibly specific EventID for a PUA detection during scanning that Defender has identified as a false detection even before the scan has completed???


Denis
 
Last edited:

My Computer My Computer

At a glance

Windows 11 Home x64 Version 26H2 Build 26300....
OS
Windows 11 Home x64 Version 26H2 Build 26300.9457
Windows Security doesn't trust
Potentially unwanted applications [PUAs] are not distrusted as such.

They are things that Defender thinks may have been copied to your computer without your explicit agreement - this does not seem to be as common as it used to be. Installing some common utility a decade ago used to require careful examination of every dialog to make sure your consent to some useless additional utility was not being assumed.

I'm glad you raised this topic. I had no idea that PUA detections were not shown in Protection history.


Denis
 

My Computer My Computer

At a glance

Windows 11 Home x64 Version 26H2 Build 26300....
OS
Windows 11 Home x64 Version 26H2 Build 26300.9457
Potentially unwanted applications [PUAs] are not distrusted as such.

They are things that Defender thinks may have been copied to your computer without your explicit agreement - this does not seem to be as common as it used to be. Installing some common utility a decade ago used to require careful examination of every dialog to make sure your consent to some useless additional utility was not being assumed.

I'm glad you raised this topic. I had no idea that PUA detections were not shown in Protection history.


Denis


It was my choice to download it in the first place. I consented to it. I saw it on MajorGeeks, and thought about trying it.


I've just ran another full scan after deleting it, and this time the scan reported no threats detected.


I'm still generally careful and vigilant though, although I slip up occasionally. I've learned the hard way over the years.


Thank you once again.
 

My Computer My Computer

At a glance

Windows 11 Home 25H2 26200.9457
OS
Windows 11 Home 25H2 26200.9457
Computer type
PC/Desktop
Manufacturer/Model
HP
@Bree,

I have never heard of an EventID 1160 as posted above. Have you?

I thought PUAs would be recorded as EventID 1117.
Defender EventIDs - MSLearn does not list 1160 but it clearly does exist.
There's nothing in the discussion at Block PUAs - MSLearn either.
[My event logs do not contain any 1160s.]

Any thoughts? Possibly specific EventID for a PUA detection during scanning that Defender has identified as a false detection even before the scan has completed???


Denis
My event log doesn't have any 1160s either, but it is the correct Event ID for PUAs

Microsoft said:
PUA events are recorded under event ID 1160.
 

My Computers My Computers

  • At a glance

    Windows 11 HomeAMD Athlon Silver 3050U8GBRadeon Graphics
    OS
    Windows 11 Home
    Computer type
    Laptop
    Manufacturer/Model
    Acer Aspire 3 A315-23-R9VY
    CPU
    AMD Athlon Silver 3050U
    Memory
    8GB
    Graphics Card(s)
    Radeon Graphics
    Monitor(s) Displays
    laptop screen
    Screen Resolution
    1366x768 native resolution, up to 2560x1440 with Radeon Virtual Super Resolution
    Hard Drives
    1TB Samsung EVO 870 SSD (from April 2026: 250GB EVO 850)
    Internet Speed
    150 Mbps
    Browser
    Edge, Firefox
    Antivirus
    Defender
    Other Info
    UPDATE - 11 April 2026: due to lid hinges starting to break up this laptop has been retired from active duty. The OS with all software and files has been migrated to my System Seven in 'Other systems' to carry on as my general purpose 'main machine'.

    I've now clean installed 25H2 and used Garlin's scripts to update Secure Boot to CA 2023 and revoke the PCA 2011 certificates. It's new role is to test secure boot issues.

    Info for 2021-2026:
    fully 'Windows 11 ready' laptop. Windows 10 C: partition migrated from my old unsupported 'main machine' then upgraded to 11. A test migration ran Insider builds for 2 months. When 11 was released on 5th October 2021 it was re-imaged back to 10 and was offered the upgrade in Windows Update on 20th October. Windows Update offered the 22H2 Feature Update on 20th September 2022. It got the 23H2 Feature Update on 4th November 2023 through Windows Update, 24H2 on 3rd October 2024 through Windows Update by setting the Target Release Version for 24H2, and 25H2 on 30th September 2025 through Windows Update by setting the Target Release Version for 25H2.
  • At a glance

    Windows 11 ProIntel® Core™ i5-520M8GB(integrated graphics) Intel HD Graphics
    Operating System
    Windows 11 Pro
    Computer type
    Laptop
    Manufacturer/Model
    Dell Latitude E4310
    CPU
    Intel® Core™ i5-520M
    Motherboard
    0T6M8G
    Memory
    8GB
    Graphics card(s)
    (integrated graphics) Intel HD Graphics
    Screen Resolution
    1366x768
    Hard Drives
    500GB Crucial MX500 SSD
    Browser
    Firefox, Edge
    Antivirus
    Defender
    Other Info
    unsupported machine: Legacy bios, MBR, TPM 1.2, upgraded from W10 to W11 using W10/W11 hybrid install media workaround.

    In-place upgrade to 22H2 using ISO and a workaround.
    Feature Update to 23H2 by manually installing the Enablement Package.
    In-place upgrade to 24H2 using hybrid 23H2/24H2 install media.
    Upgraded to 25H2 by Enablement Package.

    Also running Insider Experimental 263xx and 29xxx builds and Windows 10 as native boot .vhdx.
  • My SYSTEM THREE is a Dell Latitude 5410, i7-10610U, 32GB RAM, 512GB NVMe ssd, supported device running Windows 11 Pro.

    My SYSTEM FOUR was a 2-in-1 convertible Lenovo Yoga 11e (1st gen) type 20DA, Celeron N2930, 8GB RAM, 256GB ssd. Unsupported device. This has now been sold. It has been replaced by my System Eight.

    My SYSTEM FIVE is a Dell Latitude 3190 2-in-1, Pentium Silver N5030, 8GB RAM, 1TB NVMe ssd, supported device running Windows 11 Pro, plus Insider Beta, Experimental 263xx and 29xxx builds (and a few others) as a native boot .vhdx.

    My SYSTEM SIX is a Dell Latitude 5550, Core Ultra 7 165H, 64GB RAM, 1TB NVMe SSD, supported device, Windows 11 Pro, Hyper-V host machine. Updated to 25H2 on 30th September 2025.

    My SYSTEM SEVEN is a Lenovo Thinkpad T580, 1920x1080 touchscreen, Intel Core i7-8650U, 16GB RAM, 512GB NVMe SSD + 2nd 512GB NVMe SSD, a supported device for Windows 11. This is my current general purpose 'main machine'. The installed Windows 11 Home from my System One has been migrated to this machine. As its new home has an existing digital licence for Pro I've been able to upgrade the migrated OS from Home to Pro.

    My SYSTEM EIGHT is a 2-in-1 convertible Lenovo Yoga 11e (5th gen) type 20LN, Celeron N4120, 8GB RAM, 512GB NVMe ssd, a supported device for Windows 11. Currently running Windows 11 Pro, plus Insider Beta, Experimental 263xx and 29xxx builds as native boot vhdx.
I guess I'll have to learn to read before posting again.


Denis
 

My Computer My Computer

At a glance

Windows 11 Home x64 Version 26H2 Build 26300....
OS
Windows 11 Home x64 Version 26H2 Build 26300.9457
I asked co-pilot about event 1160 and its answer
"
"Event 1160 is triggered when Defender’s PUA protection is enabled and a program meets Microsoft’s criteria for unwanted behavior. This includes:
Bundled installers
Browser hijackers
Ad-injectors
“Optimizer” or “cleaner” tools with deceptive behavior
Software that modifies system settings without clear consent


One can configure how defender handles PUAs using group policy or powershell.
PUA protection OFF (value 0) - Defender will not protect against PUAs
PUA protection ON (value 1)- Detected items are blocked. They'll show in history along with other threats.
PUA protection in AuditMode (value 2)- detects potentially unwanted applications but takes no action. You can review information about the applications Microsoft Defender Antivirus would've taken action against by searching for events created by Microsoft Defender Antivirus in the Event Viewer.

I got these values here Block potentially unwanted applications with Microsoft Defender Antivirus - Microsoft Defender for Endpoint.
 

My Computers My Computers

  • At a glance

    Windows 11 Pro 25H2 26200.9457i9-10900 10 core 20 threads32 gbnone-Intel UHD Graphics 630
    OS
    Windows 11 Pro 25H2 26200.9457
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Optiplex 7080
    CPU
    i9-10900 10 core 20 threads
    Motherboard
    DELL 0J37VM
    Memory
    32 gb
    Graphics Card(s)
    none-Intel UHD Graphics 630
    Sound Card
    Integrated Realtek
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    2x1tb Solidigm m.2 nvme /External drives 512gb Samsung m.2 sata+2tb Kingston m2.nvme
    PSU
    500w
    Case
    MT
    Cooling
    Dell Premium
    Keyboard
    Logitech wired
    Mouse
    Logitech wireless
    Internet Speed
    so slow I'm too embarrassed to tell
    Browser
    #1 Edge #2 Firefox
    Antivirus
    Defender+MWB Premium
  • At a glance

    Windows 11 Pro 24H2 26200.9457AMD Ryzen 7 6800U32 gbintegrated
    Operating System
    Windows 11 Pro 24H2 26200.9457
    Computer type
    PC/Desktop
    Manufacturer/Model
    Beelink Mini PC SER5
    CPU
    AMD Ryzen 7 6800U
    Memory
    32 gb
    Graphics card(s)
    integrated
    Sound Card
    integrated
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    1TB Crucial nvme
    Keyboard
    Logitech wired
    Mouse
    Logitech wireless
    Internet Speed
    still too embarrassed to tell
    Browser
    Firefox
    Antivirus
    Defender
  • System 3 is non compliant Dell 9020 i7-4770/24gb ram Win11 PRO 26200.9457

Latest Support Threads

Back
Top Bottom