Windows Defender Auto Start Change Occured
-
I decided to configure my computer to automatically start Outlook 2003 when Windows loads, by adding a shortcut to “Microsoft Office Outlook 2003” to my Startup Start Menu folder (C:Documents and SettingsJimStart MenuProgramsStartup). While Outlook does start when Windows loads, an error appears in Windows Defender saying “Auto Start Change Occured” for the file: C:WINDOWSInstaller{91110409-6000-11D3-8CFE-0150048383C9}outicon.exe . The additional information is (Publisher: Not available, Category: Not Yet Classified). If I select “Permit” and then “Apply Actions” the same error occurs next time I start Windows, even though the Windows Defender history shows the “Permit” action has “Succeeded”. Obviously this is quite annoying, especially because I have permitted the outicon.exe process. Can you explain why this occurs, what is outicon.exe and, since this is a Microsoft product, why does Windows Defender not know about this process? The computer is running Windows XP SP2 with Windows Defender 1.1.1593.0.
When researching your question I came across a user with a similar problem, whereby they also receive a message about “outicon.exe” when Windows loads. The “outicon.exe” process seems to be the icon which appears in the Windows system tray when you are running Outlook 2007. This provides a shortcut to opening Outlook 2007 features as well as notifications (e.g. new emails, and also notification of the status of Outlook 2007 such as when it is synchronising with the mail server). As you mentioned, this is a Microsoft process so why this is not automatically recognised by Windows Defender is a good question, and unfortunately one for which I am unable to provide a good answer.
In any case, we want to find a way to stop Windows Defender from constantly prompting you about this process on each boot. As a starting point, visit www.microsoft.com/downloads and download the latest version of Windows Defender. The version of Windows Defender on the Microsoft website, at the time of writing, is version 1.1.1593.0 with engine version 1.1.2204.0. Even though the version of the software is the same, it may be worthwhile to re-download and re-install to ensure that you do have the absolute latest version with any necessary engine and definition updates. Additionally, when you first start Windows Defender make sure you check for updates and download any additional updates not included in the installer. Once I installed and updated Windows Defender on my test computer. I then copied the Outlook 2007 shortcut into the Startup programs folder to see what would happen. On the next boot Outlook 2007 started successfully, and the Outlook icon in the system tray (which I verified is the “outicon.exe” process) also loaded without any prompt from Windows Defender. As such, it is possible that this error has been corrected in the latest version of Windows Defender. So, I suggest that you check to see whether this resolves your problem.
Should you continue to have difficulties, then based on the experience of other users it seems that when you click “Permit” this only permits the operation for that occurrence. As such, the next suggestion is to add the path containing the “outicon.exe” process to the list of paths that Windows Defender should not scan. Before proceeding, we need to enable the display of hidden files and folders so you can see the location which you need to add to the exclusion list. Open My Computer or Windows Explorer and go to the “Tools” menu > “Folder Options”. In the window that appears, click the “View” tab and enable “Show hidden files and folders” and untick “Hide protected operating system files”. Click OK. In the warning message that appears click “Yes”. Now we can add the path to “outicon.exe” so this is excluded from the scans. Open Windows Defender then click “Tools” and “Options”. Scroll to near the bottom of the options and look underneath the “Advanced options” heading. You will see a box titled “Do not scan these files or locations”. Click the “Add” button. Navigate to the “outicon.exe” process location, which is:
C:WINDOWSInstaller{91110409-6000-11D3-8CFE-0150048383C9}outicon.exe
Click OK and then “Save”. Now, restart your computer and hopefully Windows Defender should no longer bother you about this process, as you have excluded the process from being scanned by Windows Defender.